Sanctions screening is the process of checking customers, counterparties, and transactions against sanctions lists to prevent prohibited dealings. It runs at onboarding, on an ongoing basis, and in real time on payments, and it is the main control standing between an institution and a prohibited transaction.
What is sanctions screening, in plain English?
Sanctions screening is the routine of comparing the parties and payments you handle against sanctions lists to catch anyone you are prohibited from dealing with. It runs in three places: at onboarding, when you check a new customer; on an ongoing basis, when you rescreen your book as lists change; and in real time, when you filter a payment before it settles.
It is the primary control that keeps a prohibited transaction from going through. When a name, address, or other identifier on a customer or payment matches a list entry closely enough, screening raises an alert for an analyst to review and either clear as a false positive or confirm as a true match that requires blocking or rejection.
How well it works rests on a few unglamorous things: the coverage and freshness of the lists, the quality of the data being screened, and the tuning of the matching thresholds that balance false positives against false negatives. It must also reach beyond names to indirect exposure through the 50 Percent Rule and evasion structures, because a blocked party can hide behind an entity that never appears on a list.
How screening runs across the lifecycle
- Onboard — Screen at the door. Check every new customer and connected party against the applicable lists before opening the relationship.
- Rescreen — Watch the book. Re-run the existing customer base whenever lists update, so a newly designated party is caught.
- Filter — Screen the payment. Check transaction parties in real time and hold anything that hits before it settles.
- Resolve — Disposition the alert. An analyst clears a false positive or confirms a true match and blocks or rejects, with documentation.
Who and what gets screened?
Target | What is checked |
Customers | Individuals and entities you onboard, screened at start and rescreened as lists change. |
Counterparties | The other side of a payment, plus connected parties like beneficial owners. |
Transactions | Payment parties, banks, and reference data filtered in real time before settlement. |
Ownership chains | Entities that are owned or controlled by listed parties, captured via the 50 Percent Rule. |
What it looks like in practice
In practice
A wire comes in naming an intermediary bank and a beneficiary. Real-time filtering matches the beneficiary name against an SDN entry at 88 percent and holds the payment. An analyst pulls the alert, compares date of birth and address, and finds they do not line up; the hit is a common-name false positive, cleared and documented.
The next alert is different. The beneficiary is not listed, but enrichment shows the receiving company is majority-owned by a listed party. Under the 50 Percent Rule the company is treated as blocked even though its name never appears on a list. The analyst confirms the true match, blocks the funds, and files the report. Name-only screening would have missed it.
Why it matters for operators
Sanctions screening is the control regulators look at first, because it is what stands between the institution and a strict-liability breach. If it fails, a prohibited payment settles, and in many regimes that is a violation regardless of intent. The stakes are why coverage, freshness, and tuning get so much attention: a stale list or a threshold set too loose or too tight quietly changes what gets through.
The recurring weakness is relying on name-only checks. Ownership chains and front companies let a blocked party through on a name that never appears on any list, which is exactly how sanctions evasion is designed to work. A screening program that stops at the visible name, and does not reach indirect exposure and behavioral red flags, has a gap that a determined party will use.
What to watch in the data
- List freshness. A screening list that lags the regulator's updates misses parties added since the last refresh.
- Threshold drift. Match thresholds set too tight miss variants; too loose, they bury analysts in false positives.
- Poor input data. Truncated names, missing dates of birth, and free-text fields degrade every match the engine attempts.
- Ownership blindness. Screening only names, not ownership, misses 50 Percent Rule entities and front companies.
- Rescreening gaps. Onboarding checks alone are not enough; a customer clean at signup can be listed later.
Quick questions
When does sanctions screening happen?
At three points: when you onboard a customer, on an ongoing basis as you rescreen your book against updated lists, and in real time when you filter a transaction before it settles. Each catches a different kind of exposure.
What decides whether screening works?
List coverage and freshness, the quality of the data being screened, and the tuning of the matching thresholds. Weakness in any one lets either prohibited parties through or floods analysts with noise.
Why is name-only screening a problem?
Because a blocked party can hide behind an entity that is not itself listed, through ownership chains or front companies. Screening only names misses these, so you need ownership analysis and the 50 Percent Rule alongside it.
What is the difference between a true match and a false positive?
A false positive is an alert that turns out not to be the listed party, usually a common-name coincidence, and gets cleared. A true match is a confirmed hit that triggers blocking or rejection plus reporting.
How does the 50 Percent Rule change screening?
It treats an entity owned 50 percent or more by sanctioned parties as blocked even if the entity is not named. Screening has to account for it, because a purely name-based check would clear the unlisted company.
Go deeper
- OFAC, US Treasury ↗ — Administers US sanctions programs, the SDN list, and licensing.
- European Banking Authority ↗ — EU banking regulator. Strong Customer Authentication under PSD2 and AML guidance.

