Sanctions screening is an operational process, and most failures are operational rather than legal.

What is screened. Customers at onboarding and on an ongoing basis against list updates; transactions in real time; and counterparties, vendors and employees depending on risk.

Lists. Not only the primary sanctions lists but sectoral lists, foreign lists where applicable, and internal lists of previously identified parties.

Tuning. Fuzzy matching thresholds balanced between false positives and missed matches. Tuning decisions must be documented, tested and approved. Changes made to reduce alert volume without analysis are the single most cited failure.

Ownership analysis. Entities owned at or above the threshold by blocked persons are themselves blocked though not listed. Name screening alone does not find them; ownership data does.

Alert handling. Defined dispositions, escalation criteria, timeliness standards, and quality assurance sampling. Backlogs are treated as a control failure.

Blocking versus rejecting correctly classified, with reporting on the prescribed deadlines.

Testing and audit of the screening system’s effectiveness, including injecting known test names to confirm detection.

Records of every decision, since examiners reconstruct alert dispositions years later.