Sanctions is the area of compliance where a single mistake can matter most. Unlike money laundering, where you look for patterns over time, a sanctions breach can happen in one transaction — and there is no risk appetite for getting it wrong.

This guide explains how it works, without assuming any background.

What sanctions are

Sanctions are restrictions imposed by governments or international bodies to achieve foreign policy and security objectives.

They can:

  • Prohibit dealing with named individuals, companies or vessels
  • Freeze the assets of designated parties
  • Restrict trade in particular goods
  • Limit activity in defined sectors of an economy

Crucially, these are legal obligations, not guidance. Breaching them can bring very large fines, criminal liability, and loss of access to the international banking system.

Who issues them

The United Nations Security Council issues sanctions binding on member states.

Individual jurisdictions issue their own. The most significant in practice is OFAC — the Office of Foreign Assets Control, part of the US Treasury. Its SDN list (Specially Designated Nationals) names parties whose property is blocked and with whom dealings are generally prohibited.

The European Union and the UK maintain their own regimes, and most countries have national lists.

A firm may be subject to several regimes at once, depending on where it operates, what currency it uses, and who its customers are.

Why OFAC matters even outside America

This surprises people. Because so much international business clears through US dollars and US banks, OFAC's reach extends far beyond American firms. A US nexus can arise through the currency used, US-origin goods, or US persons involved.

There are also secondary sanctions, which target non-US firms for dealing with certain sanctioned parties. The penalty is typically exclusion from the US financial system rather than a fine — which for a bank is arguably worse.

How screening actually works

Screening compares the parties you deal with against sanctions lists. It happens in two places.

Customer screening checks the people and companies you have relationships with — at onboarding, and then repeatedly whenever lists change.

Transaction screening checks the parties in a specific payment, in real time, before the money moves. This covers senders, beneficiaries, intermediary banks, and even free-text reference fields.

The distinction matters: customer screening protects the relationship, transaction screening protects the individual payment.

Why real-time matters

Once a payment reaches a sanctioned party, you cannot undo it. The breach has occurred. Detecting it the next morning is too late.

That is why sanctions screening blocks payments before release, while AML monitoring typically reviews activity afterwards.

Fuzzy matching and why false positives happen

Screening cannot simply look for exact name matches. Names are transliterated differently between scripts, abbreviated, reordered, or misspelled. If a single changed letter defeated the control, it would be useless.

So systems use fuzzy matching — flagging names that are similar enough to a listed name, scored against a threshold.

The consequence is a large volume of false positives: alerts where the name resembles a listed party but the person is demonstrably someone else. Common names generate these constantly.

Setting the threshold is a genuine risk decision. Too loose and analysts drown in noise. Too tight and a genuine match spelled slightly differently slips through.

How an analyst clears an alert

When an alert fires, the payment stays on hold. Then you compare identifiers.

Beyond the name, you look at: full name including middle names, date of birth, place of birth, nationality, address, and passport or national ID number. For companies: registered name, registration number and country of incorporation.

A clear mismatch on strong identifiers — say a different date of birth combined with a different nationality — usually justifies discounting the alert. A single weak difference, such as a slightly different address, generally is not enough.

If you cannot confirm or discount it, you escalate. You never release by default. In sanctions, uncertainty resolves upward.

The 50 percent rule

This is the concept most beginners miss, and it comes up in interviews.

Under OFAC's guidance, an entity that is owned 50% or more, directly or indirectly, by one or more blocked persons is itself treated as blocked — even though its name appears nowhere on any list.

The practical implication: screening names alone is not sufficient. You also need ownership information, because an unlisted subsidiary of a listed parent is caught.

Evasion — what it looks like

People subject to sanctions actively try to work around them. Common indicators:

  • Payments routed through unusual intermediaries or countries neighbouring a sanctioned state
  • Front companies with opaque ownership
  • Vague or generic goods descriptions
  • Changes in shipping routes, or transhipment through a third country
  • Vessels switching off their tracking systems

There is also stripping — deliberately removing identifying information from payment messages so they pass screening. This is not a data error; it is an intentional act to defeat controls, and it has been at the centre of some of the largest enforcement penalties ever issued.

Blocking versus rejecting

Two outcomes people confuse:

Blocking means the funds are frozen and held. A designated party has an interest in the property, so it cannot be returned to the sender without a licence.

Rejecting means the transaction is refused and not processed, with funds returned. This applies where the activity is prohibited but there is no property interest requiring a freeze.

Which applies depends on the regime and the facts. Both usually require reporting to the authority.

How sanctions differ from AML

This distinction is worth internalising, because it explains why the two functions feel so different.

AML is risk-based and detective. You assess risk, monitor for patterns, and report suspicion. There is judgement about how much scrutiny to apply.

Sanctions is rule-based and preventive. The prohibition is absolute. There is no risk appetite for dealing with a designated party. The control must stop the transaction before it happens.

You can take a risk-based approach to how thoroughly you screen. You cannot take a risk-based approach to whether you comply.

What good looks like

If you are asked in an interview what a strong sanctions function looks like, a solid answer covers: lists loaded promptly with the whole customer base rescreened, real-time payment screening with no coverage gaps, thresholds set on evidence and tested regularly, clean customer data with full identifiers, analysts applying a consistent discounting standard, no hidden alert backlogs, and decisions documented well enough that an outsider could follow the reasoning.