SardineCon SF/2026

Learn More

What is Deny list?

SUBSCRIBE

A deny list is a maintained set of prohibited parties, addresses, or values that screening must block or reject on a match. It is the counterpart to an allow list and the enforcement backbone of any screening program, usually built from sanctions lists plus internal risk-based additions.

What is a deny list, in plain English?

A deny list, sometimes called a blocklist or blacklist, is the set of things a firm has decided must be stopped on sight. When incoming data matches an entry, screening blocks or rejects the activity rather than letting it proceed. The entries can be parties, but also addresses, account numbers, device identifiers, IPs, or other values tied to risk.

Most of a deny list comes straight from sanctions and watchlists: the SDN List, the EU Consolidated List, the UK OFSI list, and others. On top of that, firms add their own internal, risk-based entries: known fraudsters, abusive accounts, or values flagged from past cases. The regulatory lists are mandatory; the internal additions are the firm's own risk appetite made concrete.

Because a deny list is what actually enforces prohibitions, its coverage, freshness, and tuning directly decide how well screening works. A deny list that is out of date, too broad, or missing a required list is a screening program with a hole in it.

Deny list vs allow list

What changes

Allow list

Deny list

Action on match

Exempt from blocking or repeat alerts.

Block or reject the activity.

Built from

Investigated, cleared matches.

Sanctions lists plus internal risk additions.

Failure mode

Over-broad entry suppresses a real hit.

Missing entry lets a prohibited party through.

Role

Reduce noise.

Enforce prohibitions.

What goes on a deny list

Source

What it contributes

Sanctions lists

Mandatory designated parties from OFAC, the EU, the UK, the UN, and others.

Export-control lists

Denied and restricted parties for trade, such as the DPL and Entity List.

Internal fraud data

Known bad actors, abusive accounts, and values tied to confirmed cases.

Risk-based values

Addresses, IPs, or identifiers the firm chooses to block from its own risk appetite.

What it looks like in practice

In practice

A payments firm builds its deny list from the major sanctions feeds plus internal entries for accounts tied to past fraud rings. A new customer tries to add a beneficiary whose account number matches an internal deny-list entry from a prior bust-out case, and the transfer is blocked before it leaves.

Weeks later, an audit finds one required regulatory list was never loaded into the feed. For that whole category of prohibited parties, screening had been silently passing everyone. The gap was not a bad match or a tuning problem; it was a list that simply was not there.

Why it matters to operators

The deny list is where prohibitions become enforcement, so its weaknesses become the program's weaknesses. Three failure modes recur. Stale entries that no longer match the current lists let newly designated parties through or block de-listed ones. Over-broad values flood analysts with false positives and slow real work. And worst of all, coverage gaps, where a required list was never loaded, leave an entire class of prohibited parties unchecked with no alert to signal the hole.

That last one is the quiet killer. A missing match or a tuning miss at least produces something to investigate. A list that was never loaded produces nothing, so it can persist for a long time before anyone notices, which is why coverage verification is a control in its own right.

What to watch in the data

  • Coverage completeness. Verify every required list is actually loaded; a missing list is a silent, total gap.
  • Freshness. Entries must track current designations; stale data over-blocks de-listed parties and misses new ones.
  • Over-broad values. Short or common entries generate excess false positives and bury genuine hits.
  • Internal-entry governance. Risk-based additions need a documented reason and owner, like any control.
  • Match tuning. Thresholds set the balance between catching real hits and flooding the queue; review them regularly.

Quick questions

Is a deny list the same as a blocklist or blacklist?

Yes, those are older names for the same idea: a maintained set of parties or values that must be blocked or rejected on a match. Many programs now say deny list, paired with allow list as its counterpart.

Where do deny-list entries come from?

Mostly from sanctions and watchlists, which are mandatory, plus internal risk-based additions the firm chooses, such as known fraudsters or flagged values. The regulatory portion is required; the internal portion reflects the firm's own risk appetite.

What is the worst deny-list failure?

A coverage gap where a required list was never loaded. Unlike a bad match, it produces no alert at all, so a whole category of prohibited parties goes unchecked and the problem can persist unnoticed. Coverage verification guards against it.

How does a deny list relate to sanctions screening?

Sanctions screening is the process; the deny list is the reference data that process checks against. Screening is only as good as the list behind it, so coverage, freshness, and tuning of the deny list decide how well screening performs.

Can over-broad entries hurt a deny list?

Yes. Values that are too short or common match large numbers of legitimate parties, flooding analysts with false positives and slowing real investigations. Well-scoped entries and sound match tuning keep the list effective without drowning the queue.

Go deeper

What to know alongside Deny list