Hong Kong CPD/RME HK
Book an intro

Sanctions due diligence in the real world: How much is enough?

It’s the end of the month. Your sales team wants to get a deal over the line. The customer is ready to move forward, but the sanctions check has flagged something: a possible name match and an unclear ownership structure that throws up a few question marks. How serious is it? No one can say. More importantly, how far should you investigate and who should make the final decision?

These are the moments when sanctions due diligence matters most. The available information is often incomplete, the commercial pressure is real and the next step is rarely obvious. A clean answer may not be available, yet the organisation still needs to decide whether to proceed, decline the business or escalate the matter for further review.

The challenge in sanctions compliance is that there is no standard quantity of checks that makes a transaction safe. The appropriate level of enquiry depends on an array of moving factors from counterparty to jurisdictions, payment route and proposed activity.

Sanctions compliance in the real world will generally offer one of two options. The first is that there’s no problem. For most transactions, the purpose of a check is assurance of that fact. But if there is an issue, the answer will often remain murky. In those situations, the objective is rarely certainty. At the end of the day, we need to reach a point at which the decision can be justified.

How do we do that?

Screening is the beginning of the enquiry

Sanctions screening remains an essential frontline control every business should have. Like checking credit score before making a loan, organisations need to check counterparties, beneficial owners and other relevant parties against the sanctions lists that apply to them.

First of all, don’t forget that a clean screening result will not always establish that the transaction is low risk. Sanctions can apply to entities that are owned or controlled by designated persons even where the entity is not named on a sanctions list. Sectoral restrictions, trade sanctions and prohibitions relating to particular services, goods or territories may also apply without producing a name match. These factors need to be thought about as part of the entire sanctions process.

Screening should therefore be treated as an initial question: does the information available indicate a direct or potential sanctions issue? A genuinely low-risk result would involve no relevant match, no obvious ownership or control concerns, and nothing else to suggest a risk of breach. But, if the result is anything else, then due diligence has to examine what lies behind that result.

These days, authorities increasingly examine the quality of the decision-making process. In the UK at least, OFSI does not prescribe one standard form of due diligence. It considers whether the work carried out was appropriate to the sanctions risk, the nature of the transaction and the commercial relationship. A good-faith ownership and control assessment that represents a reasonable conclusion may be mitigating. A failure to conduct appropriate due diligence may be aggravating.

Start with the sanctions risk assessment

An organisation-wide sanctions risk assessment should identify where exposure is most likely to arise. This means considering the countries in which the organisation operates, the jurisdictions through which payments or goods move, the sectors it serves, the nature of its products and services, and the complexity of its customer and supplier relationships.

That assessment will then determine the shape and scale of the organisation’s policies and screening arrangements. A business with limited international activity will have a different risk profile from a financial institution, shipping company, technology provider or exporter dealing with dual-use goods.

Each relationship or transaction then requires its own risk assessment. This should consider the counterparty’s identity and ownership, geographic exposure, business rationale, end users, and any other indicators of sanctions evasion. In the real world, this does not mean producing a lengthy written assessment for every customer or transaction. It means considering the factors that may increase the risk, applying the appropriate level of scrutiny and recording the reasoning where the risk is higher, unusual or requires escalation. 

Risk ratings help determine the amount of scrutiny required. They should direct resources rather than replace judgement. A numerical score cannot resolve contradictory information, identify an implausible commercial explanation or determine whether a designated person retains control through informal arrangements.

A low-risk rating may justify standard screening and basic verification. Higher-risk cases may require enhanced due diligence, senior approval, transaction restrictions or continuing monitoring. Where the risk cannot be brought within the organisation’s appetite, the best course of action may be to decline the activity.

Triage before investigation

Triage prevents every sanctions alert from becoming a prolonged investigation. An initial review should determine whether the issue is an obvious false positive, a routine matter that can be resolved through readily available information, or a case involving material sanctions risk. Potential name matches, opaque ownership structures, unusual intermediaries, high-risk jurisdictions, sanctioned goods and unexplained changes to the transaction should move into enhanced review.

The person conducting the triage should be able to identify the specific risk being tested. “More information is needed” is too broad. The outstanding question might be whether two similarly named people are the same person, whether a designated shareholder has genuinely divested, whether the customer is the real end user, or whether goods may be diverted after delivery.

This kind of focused approach provides a stopping point. Once the relevant question has been answered to a reasonable standard, further research should only continue where it is likely to affect the decision.

What enhanced sanctions due diligence looks like

Enhanced due diligence should be tailored to the concern. Depending on the circumstances, it may include examining corporate records and shareholder information, mapping indirect ownership, reviewing voting and contractual rights, identifying directors and senior decision-makers, conducting open-source research and seeking explanations directly from the counterparty.

The review may also need to examine the wider transaction: things like the commercial purpose or the ultimate end user. There are red flags to look out for within that process. Things like very recent incorporations, unexplained changes in ownership, a reluctance to provide information, or transactions that make little commercial sense may require additional investigation.

With this approach, due diligence should therefore test explanations rather than merely collect documents. A certificate stating that a company is the end user has limited value where its business activities do not match the product being purchased. An ownership chart should not be accepted uncritically where shares were transferred shortly before a designation or where the former owner appears to retain influence. Ultimately, the due diligence effort should be proportionate to the potential size of the deal. That doesn’t mean waving small deals through, but adding a financial lens to these questions.

Knowing when to stop

The possibility of conducting another search will almost always remain. It could also cause a situation where checks and rechecks continue ad infinitum which is rarely a viable solution. The more useful question is whether further searches are likely to change the assessment.

A defensible stopping point has usually been reached where the material risks have been identified, relevant inconsistencies have been tested, the available evidence supports a reasonable conclusion and the remaining uncertainty falls within the organisation’s risk appetite.

The resulting decision need not be a simple approval or rejection. An organisation might proceed subject to additional checks like ‘get-out’ clauses or payment controls, periodic rescreening or confirmation of the ultimate end user. You might also pause the transaction while seeking legal advice, applying for a licence or making a report to the relevant authority.

Where a concern remains unresolved and the potential consequences are serious, the inability to obtain reliable information is itself relevant to the decision. Absence of evidence is not evidence of absence, and therefore a lack of detail should not automatically be treated as evidence that no sanctions connection exists, particularly in circumstances where risk already exists.

Show how the decision was reached

A sanctions file should allow someone unfamiliar with the case to understand what happened without reconstructing the reasoning afterwards.

The record should identify the parties screened, the lists and jurisdictions considered, the sources reviewed, the ownership analysis, the red flags identified, the explanations received and the reasons those explanations were accepted or rejected. It should also record the final risk rating, the person who approved the decision, any conditions imposed and the circumstances that would trigger a new review.

This evidence becomes especially important if a breach is later identified. UK civil financial sanctions enforcement operates without requiring OFSI to prove that the organisation knew or had reasonable cause to suspect that it was committing a breach. OFSI will nevertheless consider the controls, systems and processes in place, whether they were proportionate to the risk and how the organisation managed the issue.

If you decide to continue with a transaction where the risk could not fully be mitigated, strong evidence and evidence of decision making will be critical in the event of a breach that must then be explained to the authorities. 

The consequences of weak due diligence are increasing

This evidence-first, defensible approach to sanctions risk is becoming the standard regulators expect. Both US and UK authorities are particularly interested in the workings of sanctions risk assessments. But this must also still take account of the specific rules in jurisdictions. 

Multinationals in particular need jurisdiction-specific analysis rather than a single global screening standard. Closer cooperation and information sharing between sanctions authorities also increase the likelihood that a weakness identified in one jurisdiction will attract attention elsewhere.

For instance the EU’s 21st Russia sanctions package further demonstrates the expanding scope of what may need to be checked and reviewed across jurisdictions. This latest EU package adopted on 23 July 2026, added 48 individuals and 170 entities while extending pressure across banking, crypto-assets, energy, shipping and international supply chains. Its focus on third-country institutions, crypto platforms and the businesses supporting Russia’s shadow fleet means that organisations must understand how goods, funds and services move through a transaction, rather than checking only the immediate contracting party.

HMRC’s revised naming policy adds a further consequence. HMRC has confirmed that, where appropriate, public naming will form part of compound settlements for strategic export and sanctions offences. A business that voluntarily discloses and cooperates may still face public identification. Sanctions failures can therefore become reputational events even where prosecution is avoided.

Focus on a defensible decision, not a perfect file

There is no fixed amount of sanctions due diligence that will be sufficient in every case. The appropriate level emerges from the organisation’s risk assessment, the facts of the transaction and the reliability of the information available.

A reasonable process identifies the relevant risk, applies proportionate checks, investigates material inconsistencies and escalates cases that exceed the reviewer’s authority or the organisation’s risk appetite. It also recognises when further enquiry is unlikely to alter the conclusion.

That is the practical meaning of sufficient sanctions due diligence: a decision that was reasonable when it was made, supported by evidence and capable of being explained afterwards.

Looking for more support? Join the VinciWorks sanctions webinar on Wednesday 12 August at midday UK time

Be the first to know about releases and industry news and insights.

By filling in this form you agree to share your information with VinciWorks. We take privacy seriously, click here to read our privacy notice.