Lists, tuning, alerts and the decisions that create exposure.
Esshaki Legal Media TeamCurrent as of February 2026
Sanctions screening is an operational process, and most failures are operational
rather than legal.
What is screened. Customers at onboarding and on an ongoing basis against
list updates; transactions in real time; and counterparties, vendors and
employees depending on risk.
Lists. Not only the primary sanctions lists but sectoral lists, foreign
lists where applicable, and internal lists of previously identified parties.
Tuning. Fuzzy matching thresholds balanced between false positives and
missed matches. Tuning decisions must be documented, tested and approved.
Changes made to reduce alert volume without analysis are the single most cited
failure.
Ownership analysis. Entities owned at or above the threshold by blocked
persons are themselves blocked though not listed. Name screening alone does not
find them; ownership data does.
Alert handling. Defined dispositions, escalation criteria, timeliness
standards, and quality assurance sampling. Backlogs are treated as a control
failure.
Blocking versus rejecting correctly classified, with reporting on the
prescribed deadlines.
Testing and audit of the screening system’s effectiveness, including
injecting known test names to confirm detection.
Records of every decision, since examiners reconstruct alert dispositions
years later.