Sanctions compliance is becoming increasingly difficult to treat as a simple screening exercise. Organisations are dealing with rapidly changing restrictions, complex ownership structures, international supply chains, cryptocurrency, intermediaries and increasingly sophisticated attempts to evade controls. Knowing whether a name appears on a sanctions list is only the beginning.
That complexity raises a host of questions for compliance teams. Do you need to screen every customer every day? Can you rely on your bank to stop prohibited payments? How far down the supply chain should due diligence go? What happens when a screening tool produces a possible match? And what should you do if you discover a sanctions breach after the transaction has already taken place?
These are exactly the kinds of questions we received during our recent sanctions webinar. Throughout the session, attendees asked about the day-to-day challenges of turning sanctions rules into controls that actually work, from customer and supplier due diligence to cryptocurrency, blocked payments and possible breaches.
The questions highlight how sanctions compliance has moved far beyond checking names against a list. Organisations need to understand ownership and control, where goods and funds are ultimately going, who is involved in a transaction and when unusual activity should be escalated.
The FAQs below bring together some of the key questions submitted before and during the webinar, along with our answers. They cover some of the most common sanctions compliance challenges organisations are facing and what effective controls can look like in practice.
1. Are there any case studies where businesses have been fined for failing to act on suspicions that they were dealing in sanctioned goods?
There are UK enforcement cases involving businesses dealing in sanctioned goods, although relatively few published cases are framed specifically as a company having suspicions about goods and simply failing to act on them.
A recent example is Petrofac Facilities Management Limited, which paid a £569,157 settlement to HMRC in June 2026 after making sanctioned industrial goods available to persons connected with Russia and for use in Russia. HMRC said the breaches arose while the company was divesting its Russian operations and noted weaknesses in internal controls.
There is also a useful OTSI case study showing the opposite outcome. A UK branch of a multinational bank identified payments connected with prohibited Russian goods, carried out enhanced due diligence, stopped the payments and reported the matter. OTSI concluded that the bank had not breached the sanctions because it had intervened before the payments were processed.
The lesson is that sanctions red flags should not simply be recorded and ignored. They should trigger investigation, escalation and, where appropriate, the suspension of the transaction. This is particularly important because many UK trade sanctions breaches can now attract civil penalties on a strict liability basis, without OTSI needing to establish that the business knew it was breaching sanctions.
2. Is an SRA-regulated firm required to check whether an opposing party or other third party is sanctioned, even if that party is represented by another regulated law firm?
Yes, although the level of checking should be proportionate to the risk.
The SRA specifically warns firms that sanctions risk does not stop with their own clients. Counterparties, beneficial owners, third-party funders and others involved in a transaction may create sanctions exposure. Crucially, the SRA says firms cannot rely on another party’s assurance that someone is not sanctioned. At a basic level, firms should screen counterparties against the UK Sanctions List and consider ownership and control.
That does not mean a solicitor must conduct the same level of due diligence on every opponent that they would conduct on their own client. The SRA acknowledges that less information may be available about counterparties and says checks should increase as the risk increases.
So, the fact that the opposing party has its own regulated solicitors does not remove your firm’s responsibility. If, for example, your firm is transferring settlement funds to a sanctioned counterparty, it cannot simply assume the other solicitors have dealt with the sanctions issue.
3. Given the UK’s strict liability sanctions regime and the difficulty of establishing crypto asset provenance, should UK law firms avoid all transactions where source of wealth or source of funds checks identify crypto assets?
No. The presence of crypto assets should be regarded as a risk factor, rather than an automatic reason to refuse the transaction.
Crypto assets fall within the UK’s financial sanctions regime, and they can create additional risk because funds may move rapidly across borders, through exchanges, wallets, decentralised finance and mixing services. However, it is not correct to say that their provenance is inherently impossible to understand. OFSI’s crypto assets threat assessment specifically discusses the use of blockchain analytics to identify both direct and indirect exposure to designated persons and recommends examining multiple transaction ‘hops’.
A law firm should therefore take a risk-based approach. Where crypto appears in the source of funds or source of wealth, that may justify additional questions about the wallet history, exchanges used, how the assets were acquired, the jurisdictions involved and whether mixers, sanctioned platforms or other higher-risk services appear in the chain.
If the firm cannot obtain a reasonable understanding of the source of the assets, or blockchain analysis identifies unresolved links to sanctioned parties, that may be a reason not to proceed. But a blanket policy of refusing any matter involving crypto goes further than current SRA or OFSI guidance requires. The SRA itself identifies crypto as something firms should assess the risk of, rather than something they must automatically reject.
4. What is your advice for building a proportionate sanctions programme for a niche, lower-risk industry, while still meeting legal obligations?
The key distinction is that the law itself is not risk-based, but the compliance programme you use to prevent breaches can be.
For a genuinely lower-risk organisation, a sanctions programme does not necessarily need the same infrastructure as a global bank or commodities trader. A proportionate programme might consist of a documented sanctions risk assessment, clear responsibility within the business, screening at onboarding, appropriate ownership and control checks, a procedure for escalating potential matches, sanctions provisions in relevant contracts, staff training and periodic or event-driven re-screening.
More intensive due diligence can then be reserved for situations where something changes the risk: an opaque ownership structure, a high-risk jurisdiction, an unusual intermediary, an unexpected payment route, goods subject to trade controls or a connection with a designated person.
OTSI expressly considers whether a company’s due diligence and compliance systems were proportionate to its size, sanctions exposure and resources when deciding how to respond to a breach. Poor or inadequate due diligence can conversely be an aggravating factor.
So the goal is not to replicate a bank’s compliance department. It is to be able to demonstrate that you understand where sanctions risk could realistically arise in your business and have controls proportionate to that exposure.
5. Under the Cyprus and EU sanctions framework, must a company cease operations merely because a sanctioned individual indirectly owns 40% of it, or can it continue operating provided that individual’s shares and economic rights are frozen?
A 40% holding does not, by itself, automatically mean that the entire company is sanctioned.
Under the EU’s current ownership and control guidance, an entity is generally regarded as owned by a listed person where the person holds 50% or more of the proprietary rights or a majority interest. However, ownership is only part of the test. A person with less than 50% may still control the company through voting arrangements, board appointment rights, dominant influence or other means.
Therefore, with a 40% indirect holding, the company would need to analyse whether the sanctioned shareholder exercises control in practice. If the company is neither owned nor controlled by the listed person, EU Commission guidance says that the company itself is, in principle, not automatically subject to the asset freeze.
The sanctioned person’s own shares must nevertheless be frozen. Current EU guidance also makes clear that the individual cannot exercise the voting rights attached to those frozen shares. Funds or economic resources must not be made available to them, directly or indirectly.
So it may be possible for the company to continue its otherwise lawful operations, but only where the sanctioned person’s assets and rights can genuinely be ring-fenced and they are not exercising control or receiving a prohibited benefit. Cyprus implements EU restrictive measures directly and its National Sanctions Implementation Unit handles sanctions implementation and licensing matters, so a live case involving a 40% sanctioned shareholder should be assessed with Cyprus-specific legal advice and, where appropriate, referred to the NSIU.
7. For a global group with suppliers, subcontractors and subsidiaries around the world, what are reasonable sanctions-compliance steps, and how do you avoid taking compliance too far?
For a global organisation, trying to apply maximum due diligence to every supplier, subcontractor and transaction is unlikely to be an efficient approach. The better model is a consistent group-wide minimum standard combined with additional controls where the risk warrants them.
Start by understanding which sanctions regimes apply to each group entity and where the main exposure lies. Then differentiate between relationships. A low-value supplier operating transparently in a low-risk jurisdiction will generally justify fewer checks than an intermediary with opaque ownership operating across Russia-facing or sanctions-sensitive markets.
Screening should cover relevant parties and ownership structures, with enhanced checks where risk factors emerge. Payment routes, end users, intermediaries, changes in beneficial ownership and unusual requests should also be capable of triggering further review. Contracts should support sanctions compliance and escalation, and the group should retain evidence of why particular levels of due diligence were considered appropriate.
Regulators do recognise proportionality. OTSI considers whether systems are proportionate to the organisation’s size, sanctions exposure and resources. But proportionality relates to how you manage the risk; it does not create permission to breach sanctions because a relationship had previously been classified as low risk.
The balance is therefore not between checking everything and checking nothing. It is about being able to explain why your controls are focused on the areas where a breach is realistically most likely to occur.
8. How does the position change where the parent company is UK-based but a US subsidiary performs work on behalf of the parent?
This creates an important overlap between UK and US sanctions regimes.
The UK parent remains subject to UK financial sanctions wherever it operates. A US-incorporated subsidiary, meanwhile, is a US person for OFAC purposes and must comply with applicable US sanctions.
The US subsidiary does not automatically become a UK person simply because it is owned by a UK company. However, OFSI specifically states that a UK nexus may arise where a UK company directs the overseas actions of a local subsidiary.
That means a UK parent should not treat its overseas subsidiary as a means of carrying out activity that the parent itself would be prohibited from undertaking. If the subsidiary is acting directly on instructions from the UK parent, the UK sanctions position needs to be considered alongside the US one.
In practice, the group should look at who is contracting, who is giving instructions, who approves the transaction, who receives the benefit, how payment is made and which entities or individuals are involved. There may be circumstances where US rules are stricter than UK rules, or vice versa, so both regimes need to be considered rather than simply applying the law of the subsidiary’s location.
9. How should a business assess the risk of indirect sanctions exposure?
Indirect exposure is one of the more difficult areas of sanctions compliance because the sanctioned person may never appear as the immediate customer or supplier.
The assessment should look beyond name screening and consider the whole relationship and transaction. That includes beneficial ownership and control, parent and subsidiary relationships, intermediaries, third-party funders, banks and payment routes, the destination and end use of goods, jurisdictions involved and whether a designated person could ultimately receive funds or an economic benefit.
Ownership structures deserve particular attention. Under UK financial sanctions, an unlisted entity can still be subject to restrictions if it is owned or controlled by a designated person. This is why simply obtaining a ‘no match’ against the UK Sanctions List is not always sufficient.
Risk indicators such as recently altered ownership structures, shell companies, unexplained intermediaries, third-party payments, reluctance to provide ownership information, complex routing through multiple jurisdictions or connections with sanctioned countries should lead to enhanced due diligence.
The depth of investigation should then increase with the level of risk. The objective is not to prove that there is zero conceivable connection to a sanctioned party. It is to identify realistic routes of direct or indirect exposure, investigate material red flags, document the conclusions reached and have a clear process for escalating cases where the position remains uncertain. This approach is consistent with both OFSI’s ownership and control guidance and the SRA’s expectation that sanctions checks become more extensive as the identified risk increases.
10. Do we need to screen every customer every day?
Not necessarily. There is no universal rule requiring every customer to be screened every day. The frequency should reflect your risk, customer base, transactions and systems. A low-risk domestic relationship may justify periodic screening, while a high-risk international customer, particularly one receiving sensitive products or operating through higher-risk jurisdictions, may require much more frequent or automated monitoring.
What matters is that your controls can respond quickly when sanctions change. Existing customers should be re-screened regularly and when something material changes, such as ownership, destination, payment route or a new designation. The approach should be documented and proportionate to the risk. UK guidance specifically recommends regular review of the UK Sanctions List and enhanced screening for higher-risk transactions.
11. Can we rely on our bank to block prohibited payments?
No. The bank is an additional control, not a substitute for your own sanctions compliance.
Your bank may not know what you know about the customer’s ownership and control, the end-user, the goods or services involved, or the purpose of the transaction. Sanctions can also prohibit supplying goods, services, funds or economic resources even where no payment is ultimately processed. Your organisation therefore needs its own controls rather than assuming the banking system will catch everything.
12. Is a supplier sanctions warranty enough?
No. It is useful, but it does not replace due diligence where the risk requires further investigation.
A warranty gives you contractual protection if the supplier provides false information, but it does not independently establish who owns or controls the supplier, where goods will ultimately go or who the end-user is. In higher-risk situations, declarations should be checked against reliable independent sources and supported by appropriate ongoing monitoring. UK guidance specifically recommends cross-checking customer declarations rather than relying on them alone.
13. What should we do with a possible screening match?
Do not reject it immediately, but do not clear it simply because the name is common either. Compare identifiers such as date of birth, nationality, address, registration details, aliases, directors and ownership information to establish whether it is a genuine target match.
If you cannot resolve the match confidently, pause the relevant activity and escalate it for review. If you establish that it is a designated person, or an entity owned or controlled by one, the applicable restrictions must then be followed. For an asset freeze, this can mean immediately freezing funds or economic resources, stopping prohibited dealings and making any required report to OFSI. OFSI can also be contacted where a potential match remains unresolved.
14. Are cryptocurrency transactions automatically high risk?
No. A transaction is not automatically high risk simply because cryptocurrency is involved, but crypto can create additional sanctions risks that need to be understood.
UK financial sanctions apply to cryptoassets just as they do to other funds and economic resources. Risk will depend on factors such as the parties, wallets, exchanges or platforms involved, jurisdictions, transaction history and whether there is exposure to sanctioned or associated wallets. An organisation accepting crypto without the ability to investigate relevant wallet activity or transaction flows may be taking on risk it cannot adequately manage. OFSI has specifically identified direct and indirect exposure to designated persons as a significant threat in the cryptoasset sector.
15. What if we discover a breach after it has happened?
Act quickly. Stop any continuing prohibited activity, preserve the relevant records and escalate the issue internally to compliance or legal advisers. Establish whether assets need to be frozen and whether there is a mandatory reporting obligation.
For example, certain UK firms must report to OFSI as soon as practicable where they know or reasonably suspect that a person is designated or that a relevant financial sanctions prohibition has been breached. Even where a disclosure is voluntary rather than mandatory, prompt and complete self-disclosure can be taken into account as a mitigating factor in UK enforcement.
Do not quietly alter records, reroute payments or reverse transactions without first understanding the legal position, as dealing with frozen assets can itself create further problems.
16. How far down the supply chain should due diligence go?
There is no universal number of tiers. The depth should reflect the sanctions risk rather than stopping automatically at the first or second supplier.
Ordinary goods in a low-risk context may justify relatively straightforward checks. Sensitive or controlled products, higher-risk destinations, agents, subcontractors, freight forwarders, opaque ownership or unusual shipping arrangements may require you to look further. In higher-risk transactions, you may need to understand not only the direct customer but also beneficial ownership, intermediaries, the end-user, end-use and route by which the goods will reach them.
The EU takes a similar risk-based approach and says there is no one-size-fits-all model for sanctions due diligence.
17. What are the biggest sanctions compliance mistakes organisations make?
One of the biggest is treating sanctions as nothing more than a list-screening exercise. Screening is important, but serious sanctions risks often involve ownership and control, diversion, end-use, technology, shipping, intermediaries and attempts to restructure transactions.
Another major mistake is allowing commercial teams to solve sanctions problems commercially. If a bank blocks a payment or compliance raises a concern, the instinct may be to find another company, payment route, bank or intermediary to get the deal through. That should be an immediate red flag. Depending on the circumstances, restructuring a transaction to get around sanctions restrictions can amount to prohibited circumvention.
The right response to a sanctions problem is to stop, understand why the control was triggered and resolve the legal or compliance issue before proceeding.
18. How do sanctions compliance expectations differ for consulting firms compared with banks or law firms?
The key difference is risk exposure. Banks and law firms tend to have more formalised sanctions controls because they handle payments, client money and higher-risk transactions.
Consulting firms may have less direct exposure, but that doesn’t mean they’re outside the risk. They need to look at who they work for, where clients and projects are located, what services they provide, and whether technology or payments are involved.
So the expectation is still proportionate. Understand your exposure, screen where appropriate, train relevant staff, and have a clear process for pausing and escalating anything suspicious. The programme may look different from a bank’s, but the fundamental principle is the same, that is know where your sanctions risk is and manage it.
19. What are best practices around monitoring sanctions related controls within professional service businesses?
For professional services firms, best practice is to test whether the controls actually work, rather than simply checking that a sanctions policy exists.
That means regularly reviewing screening, checking that alerts are being handled correctly, testing escalation and approval processes, and looking at whether changes in clients, ownership, jurisdictions or payment arrangements are being picked up.
And importantly, test the people as well as the systems. Run realistic scenarios and ask, if a client became sanctioned today, would the right people know what to do, and could they actually pause the activity? That’s often where weaknesses become visible.
Missed our webinar? It's on demand – Sanctions compliance now: How to future-proof your business against escalating risk and enforcement
Watch it here →