Sanctions List Screening: Duties, Workflow & Automation

Sanctions list screening compares people and organizations with the sanctions lists that apply to a business. Its purpose is to prevent prohibited funds or economic resources from being made available to designated persons or relevant entities they own or control.
EU sanctions regulations do not generally prescribe one particular screening tool or a universal screening frequency. They do, however, impose directly applicable asset freezes and prohibitions on making funds or economic resources available. Companies therefore need a proportionate process that identifies relevant counterparties, ownership links, and transactions early enough for a defensible decision.
It is Thursday morning and the sales team is celebrating a major new order. Two days later, the bank holds a payment because the name of an indirect shareholder resembles an entry on a sanctions list. The company must now establish more than whether a prohibition ultimately applies. It also needs to show which data was screened, which list version was current, and why the transaction was released or stopped.
Sanctions screening is not limited to exports. The prohibition on making funds or economic resources available can cover payments, goods, software, and services as well as indirect benefits through owned or controlled entities.
What is sanctions list screening?
Sanctions list screening, also called sanctions screening or denied-party screening, compares names and additional identifiers against the sanctions lists relevant to a transaction.
The name comparison is only the first step. A defensible review answers three questions:
- Identity: Is the counterparty actually the designated person or merely someone with a similar name?
- Ownership and control: Is an unlisted company owned or controlled, directly or indirectly, by a designated person?
- Legal effect: Which sanctions programme and which specific restriction apply to the proposed activity?
Sanctions screening is not the same as a complete export-control review. Country embargoes, controlled-goods lists, end-use checks, and licence requirements must be assessed separately. A clean name-screening result does not automatically make a shipment lawful.
Who needs to conduct sanctions list screening?
It is a mistake to view sanctions lists as a concern only for global exporters. Any operator acting within the scope of an EU sanctions regulation must observe its prohibitions. That can affect manufacturers, online retailers, freight forwarders, software vendors, banks, and professional-service providers, including in a transaction that stays within Germany or the EU.
The decisive factor is not simply whether goods cross a border. A payment, loan, software licence, consultancy service, or another economic benefit may also constitute making funds or economic resources available.
There is no universal statutory sentence saying that every company must screen every contact every day. The control framework should reflect the applicable sanctions regimes, products, countries, payment routes, counterparties, and risk exposure. A recurring exporter or a business dealing with complex corporate groups will typically need more screening checkpoints than a company with only local and transparent relationships.
A similar name is not yet a sanctions breach, but every potential match needs a traceable decision.
Which people and organizations should be screened?
A sanctions check should not stop at the invoice or delivery address. Depending on the transaction, relevant parties may include:
| Screening area | Typical parties and data | Why it matters |
|---|---|---|
| Counterparties | Customers, suppliers, distributors, sales partners | Direct contractual, payment, or service relationship |
| Ownership and control | Shareholders, parent companies, controlling persons | Restrictions may extend to unlisted entities that are owned or controlled by designated persons |
| Transaction and logistics | Consignee, end user, freight forwarder, carrier, intermediary | Economic resources can be provided indirectly or through several participants |
| Payment | Account holder, payee, participating banks | Different payment routes can introduce additional parties and risks |
| Own organization | Employees or officers where a concrete availability risk exists | Payments and benefits must remain lawful; employment and data-protection law require separate assessment |
For legal entities, a list comparison alone is not enough. European Commission guidance explains that asset freezes can also cover the assets of an unlisted entity when it is owned or controlled by a designated person.
It is important not to confuse this test with identifying a beneficial owner for anti-money-laundering purposes. Familiar AML ownership thresholds do not automatically answer the sanctions ownership-and-control question. The criteria in the applicable sanctions measure and the practical ability to exercise control must also be assessed.

When should sanctions screening take place?
A one-time check when a customer record is created is often insufficient. Lists, company details, and ownership structures can all change. Useful checkpoints include:
- before starting a business relationship, while the contract, delivery, or service can still be held,
- when master data or ownership information changes,
- before critical transactions, such as order release, goods issue, or payment,
- after relevant list updates, and
- on a risk-based recurring schedule for existing counterparties.
In a digital export workflow, screening can take place before the export declaration, MRN, and EAD are released. That allows a potential match to be resolved before the goods, documents, and transport are already moving.
The right timing depends on the process. If screening happens only when the shipping label is printed, purchasing may already be complete, the goods produced, and the payment initiated. If it happens only during onboarding, a later designation may go unnoticed. A sound process therefore combines several events without forcing teams to review every unchanged record manually each time.
Which sanctions lists are relevant?
The lists a company needs depend on the law that applies and on the particular transaction. Connecting the largest possible number of lists is not automatically the safest approach; what matters is a documented and justified scope.
EU consolidated financial sanctions list
For operators within EU jurisdiction, the EU consolidated financial sanctions list is the central starting point for individual financial sanctions. The legal acts and their annexes published in the Official Journal remain authoritative. The consolidated list makes screening easier, but it does not replace reviewing the relevant sanctions programme, restrictions, and available derogations.
UN Security Council Consolidated List
The United Nations Security Council maintains a consolidated list of the individuals and entities designated by its sanctions committees. Relevant UN measures are implemented for EU operators through EU legal acts. The UN list is therefore an important source, while the concrete legal consequence follows from the law applicable in the relevant jurisdiction.
US OFAC and BIS lists
Well-known US lists include the OFAC SDN List, other OFAC lists, the BIS Entity List, and the Denied Persons List. Their effects differ substantially. They may become relevant where there is a legally meaningful US nexus, such as participating US persons or items and technology subject to the US Export Administration Regulations.
A US-dollar payment or the use of US software does not by itself mean that every US sanction automatically applies to a non-US company. Those factors can nevertheless affect banks, supply chains, and the legal assessment. The specific US nexus should be reviewed on its facts rather than inferred from a single characteristic.
UK Sanctions List and Swiss SECO data
For business involving the United Kingdom or Switzerland, the UK Sanctions List and sanctions data published by the Swiss SECO may also be relevant. Since 28 January 2026, the UK Sanctions List has been the only current source for all UK sanctions designations; the former OFSI Consolidated List has closed.
How does a sanctions screening process work?
A traceable workflow typically consists of six steps.
1. Define scope and relevant lists
The company documents which parties, data sources, and sanctions regimes matter for each process. Ownership of decisions and escalation routes need to be clear before the first potential match appears.
2. Prepare reliable data
Names alone are often insufficient. Date of birth, address, nationality, registration data, aliases, and ownership links help distinguish people and companies. Better master data reduces unnecessary matches.
3. Run automated name matching
Screening software normalizes spellings and accounts for aliases, transliteration, and fuzzy similarities. It may recognize, for example, that “Müller” and “Mueller” are related spellings. Thresholds need to expose meaningful variation without flooding the process with unusable alerts.
4. Review potential matches
A system-generated match is only a potential match. It should neither be treated automatically as a confirmed breach nor dismissed without review. The responsible reviewer compares additional identifiers, identifies the relevant sanctions programme, and assesses ownership, control, and the proposed transaction.
5. Release, block, or escalate
If identity can be ruled out reliably, the case can be released with a recorded rationale. If reasonable doubt remains, the transaction is held and escalated to the compliance function, qualified legal counsel, or the competent authority. A technical override cannot replace a required licence or derogation.
6. Record the decision and rescreen
The audit trail should show when a particular record was checked against a particular list version, which similarity triggered the review, what additional identifiers were considered, and who made the decision for what reason. A change to a list or master record should be able to trigger another check.
What should a company do with a match or false positive?
Similar names are inevitable. Common family names, different transliterations, and limited identity data frequently produce false positives. A defined review workflow prevents both premature shipment stops and unsafe releases.
- Place a temporary hold without treating the alert as a confirmed designation.
- Compare the name, aliases, date of birth, address, registration data, and other identifiers.
- Review the original list entry and the specific sanctions programme.
- Assess the counterparty's ownership and control structure.
- Decide under the company's review and escalation rules, ideally with a second pair of eyes.
- Record the rationale and evidence used for the decision.
A resolved similarity may be stored as a documented false positive. It should not be suppressed indefinitely regardless of future changes to the counterparty or list entry.
Why manual sanctions list checks do not scale
Official search tools are useful for individual checks. A company with many customers, suppliers, and daily transactions faces a different problem:
- sanctions lists and identifiers change regularly,
- names appear in different alphabets, spellings, and orders,
- ownership structures are not visible from the counterparty's name,
- recurring checks need to run at the correct process event, and
- decisions need to remain traceable months or years later.
Spreadsheets and manual portal searches distribute those tasks across individual people and files. Checks are then more likely to occur late, similar matches can receive inconsistent decisions, and evidence may be difficult to retrieve.
Automating sanctions list screening: essential capabilities
An automated sanctions screening tool should do more than return “match” or “no match.” It needs a controlled review process around the matching engine.
Useful capabilities include:
- current and clearly versioned list data,
- fuzzy matching for spelling variants, aliases, and transliteration,
- risk-appropriate thresholds rather than one rigid global score,
- additional identifiers and ownership information,
- a defined review, release, and escalation workflow,
- automatic rescreening after relevant changes,
- role controls and four-eyes approval, and
- an exportable audit trail for internal and external reviews.
Through a customs API and ERP integration, screening can be triggered where data is created or changed: when a partner is created in the CRM, an order is released in the ERP, goods leave the WMS, or a payment is prepared.
Integration does not remove professional responsibility. It allows unchanged cases to flow automatically, directs potential matches to the right reviewer, and records decisions consistently. That reflects the principle behind controlled customs automation: standard cases keep moving while exceptions become visible and reviewable.
Checklist for a defensible screening programme
A company should be able to answer at least the following questions:
- Which sanctions regimes apply to our entities, goods, countries, and payment routes?
- Which business and transaction parties are screened at which process event?
- How do we identify and assess ownership and control?
- How current and traceable is our sanctions-list data?
- Which master data is available to confirm identity?
- Who reviews potential matches and who may approve a release?
- When is a transaction stopped or escalated to specialists or authorities?
- Which changes trigger rescreening?
- How long and in what form are screening results retained?
- How are data protection, access rights, and deletion rules addressed?
Conclusion: sanctions screening is a process, not a search box
Sanctions list screening extends far beyond an occasional export to a high-risk destination. Companies need to prevent funds or economic resources from being made available directly or indirectly to designated persons or relevant organizations they own or control.
A defensible process combines four elements: appropriate list data, complete counterparty information, professional match review, and a traceable record. Automation can accelerate matching and trigger reliable rescreening. Deciding a potential match remains a compliance task that needs clear ownership and, where necessary, specialist advice.
If you want to connect sanctions screening with your customs, ERP, and logistics workflows, talk to our digital customs process specialists about the points at which screening and escalation can be integrated effectively.
Official sources
- European Commission: overview of EU sanctions and the consolidated financial sanctions list
- European Commission: enhanced due diligence guidance against sanctions circumvention
- Deutsche Bundesbank: frequently asked questions on financial sanctions
- German Foreign Trade and Payments Act: section 18 on criminal offences and section 19 on fines (current German text)
- OFAC: Sanctions List Service
- BIS: Entity List and Denied Persons List
- United Nations: Security Council Consolidated List
- UK government: UK sanctions
- SECO: search for sanctioned individuals, entities, and organizations
This article provides a general overview and does not replace legal advice on a particular transaction, sanctions regime, or potential match.
More articles

EAD, MRN & proof of exit
The four stages of the export procedure explained clearly
July 27, 20268 min read

Our contribution to even Report #4
Customs as a strategic lever in transport management
June 23, 20267 min read

ICS2 and ENS at the EU border
Why freight needs clean pre-arrival data
March 29, 20264 min read





