The Only Sanctions Screening Checklist You Need in 2026

01 August 2026 | Industry Intel

Sanctions violations most often come from programs that were already screening. OFAC’s 2025 enforcement record totaled $265 million in penalties across 14 actions

In those cases, enforcement findings point to a consistent pattern of controls scoped too narrowly, thresholds set without documentation, ownership structures left uninvestigated, and monitoring that ended at onboarding.

Passing an OFAC examination or a correspondent bank due diligence review requires every control to be documented, owned, tested, and traceable to a decision record.

This sanctions screening checklist covers eight control areas, giving compliance teams a clear view of where their program stands and what it needs to demonstrate before the next review arrives.

Key takeaways:

  • A sanctions program and a defensible sanctions program are not the same thing

Most violations come from programs that were already running. The difference is whether every control is documented, owned, and backed by evidence.

  • Eight control areas determine whether a program holds up under scrutiny 

This checklist covers scope, list coverage, ingestion assurance, threshold configuration, alert disposition, continuous monitoring, and reporting obligations.

  • Reporting obligations have fixed deadlines 

Blocking reports, annual property reports, and voluntary self-disclosure each carry specific timelines that need to be mapped before a violation occurs.

  • Watchlist screening and adverse media together close the pre-designation window 

Adverse media can flag risk before a formal designation arrives. Programs that rely on watchlists alone carry exposure in that interval.

  • Sigma360 produces the evidence each checklist item requires

From ingestion assurance logs to audit-ready decision trails, Sigma360 is built around the eight control areas this checklist covers.

The sanctions screening checklist for 2026

Sanctions screening checklist

1. Conduct and document a sanctions risk assessment

Owner: Chief Compliance Officer or designated sanctions officer 

Review frequency: Annually, and whenever the business adds a new product, geography, payment rail, or correspondent relationship

The sanctions risk assessment is the document every other control in the program builds from. OFAC’s Framework for Compliance Commitments identifies it as one of five essential program components, requiring institutions to develop and routinely update it.

Most programs treat the risk assessment as a launch deliverable, operating against a document that no longer reflects actual exposure as the business grows. The assessment must address which sanctions regimes apply to the business, which products and services carry the highest exposure, and which customer segments and jurisdictions present elevated risk. It should also map how existing controls address each identified risk area.

Evidence to produce:

  • Dated and signed risk assessment document
  • Change log recording each update and the trigger that prompted it
  • Sign-off from senior management or the board

2. Confirm list coverage across all applicable regimes

Owner: Compliance or sanctions operations 

Review frequency: Quarterly, and whenever a new sanctions regime is introduced

Which sanctions regimes an institution must screen against depends on where it operates, which payment corridors and currencies it processes, and which regulators or correspondent banks have jurisdiction over its activity.

The table below maps the core regimes most regulated institutions must cover.

 

Sanctions regime Administering authority Coverage requirement
OFAC SDN List and non-SDN consolidated lists US Department of the Treasury Required for all US persons and transactions touching the US financial system
UN Security Council consolidated list United Nations Binding on all UN member states under Article 25 of the UN Charter
EU consolidated financial sanctions list European Commission Required for EU persons, entities incorporated under EU member state law, and conduct within EU territory
UK financial sanctions list OFSI / FCDO Required for UK-established entities, maintained independently of the EU since Brexit
Regional and national lists SECO, FINTRAC, AUSTRAC, MAS, and others Required for institutions with operations or customers in the relevant jurisdiction

 

These regimes publish on independent schedules and do not automatically mirror each other. Screening against one while ignoring the others leaves uncovered exposure across every jurisdiction where a different regime applies, which is precisely what FATF Recommendation 6 requires countries to address without delay.

A written list-coverage policy names each regime in scope, explains the rationale for any exclusion, and assigns a named owner to monitor each authority for updates.

Evidence to produce:

  • Written list-coverage policy naming each regime in scope
  • Documented rationale for any regime excluded from coverage
  • Named owner for each list source

Read more: From watchlist updates to early risk signals: what OFAC’s latest Iran sanctions show about modern screening

3. Verify list ingestion and refresh completion

Owner: Technology or compliance operations 

Review frequency: After every scheduled refresh, with a documented exception process for failures

List coverage and list assurance serve different functions. Having a contracted data feed confirms what a program is supposed to screen against, not whether the last refresh completed successfully. When a feed fails to update, the compliance team screens against stale data while believing it has current coverage. 

Under OFAC’s strict liability standard, intent is not a defense, and a missed cycle is a violation regardless of whether the institution knew it had occurred.

Ingestion assurance bridges contracted coverage and confirmed coverage, verifying that each refresh ran to completion, the data loaded correctly, and the screening engine is querying the current file.

Evidence to produce:

  • Automated refresh confirmation log with timestamp and record count per list
  • Exception log documenting any failed refresh, the cause, and the remediation action taken
  • Alert or escalation process triggered when a refresh fails to complete within the defined window

4. Define and document screening scope beyond customer names

Owner: Compliance, with input from operations and onboarding 

Review frequency: Annually, and whenever onboarding data collection changes

Name-only screening is among the most consistently cited deficiencies in OFAC enforcement guidance. Sanctioned parties routinely operate through beneficial owners, nominee directors, and layered corporate structures that never appear on a published list by name. Limiting scope to the customer name alone leaves that exposure undetected.

A complete program screens across four areas. Each category below represents a distinct layer of exposure that name-only matching cannot reach.

Individuals and entities:

  • Customers, directors, beneficial owners, and authorized signatories
  • Agents, introducers, third-party referrers, and known counterparties

Payment parties:

  • Originating and beneficiary banks, SWIFT/BIC codes, IBANs, and intermediary financial institutions
  • Transactions routed through high-risk payment corridors

Ownership structures:

  • Entities owned 50% or more in aggregate by blocked persons under the OFAC 50% Rule
  • Layered corporate structures, nominee relationships, and shared directorship networks

Assets and identifiers:

  • Vessels, aircraft, registration numbers, and crypto wallet addresses
  • Known aliases, including transliterations and script variants

Any area excluded from screening should be documented with a named rationale and explicit approval.

Evidence to produce:

  • Written scope document covering each screening category
  • Documented rationale for any category excluded, with named approval
  • Record of the data fields collected at onboarding to support each scope category

What a complete sanctions screening program covers

Read more: The nuances of effective sanctions screening

5. Set and document matching thresholds by risk segment

Owner: Compliance, with sign-off from the sanctions officer 

Review frequency: Semi-annually, and after any significant change in customer population or product mix

Matching thresholds determine what the screening engine flags and what it lets through. Set too tight, a threshold misses near-matches that warranted review. When configured too broadly, it floods analysts with low-confidence alerts, producing a backlog where a genuine match can sit unreviewed long enough for a prohibited transaction to settle. 

OFAC’s compliance framework requires institutions to demonstrate that their configuration is risk-based and deliberate. An undocumented setting cannot satisfy that requirement regardless of how well it performs in practice.

Configuration needs to reflect the actual risk profile of each segment. High-risk corridors and complex ownership structures warrant tighter settings with manual review for near-matches. High-volume payment flows, on the other hand, call for AI-assisted contextual scoring to maintain coverage without generating alert volumes that overwhelm the review queue.

Evidence to produce:

  • Threshold documentation recording the setting, rationale, segment, and approval date for each configuration
  • Change log for threshold adjustments
  • Periodic testing results confirming thresholds perform as intended against the current customer population

6. Build and test alert disposition and escalation procedures

Owner: Compliance operations, with escalation paths to senior compliance or legal teams

Review frequency: Annually, with scenario testing at least semi-annually

An alert is the start of a compliance decision, not the output of one. How that decision is reviewed, documented, and escalated determines whether a screening result converts into a defensible record.

Three failure modes appear most often across enforcement findings:

  • Undocumented decisions: An alert reviewed and closed with no written rationale leaves no evidence that a human applied judgment to the result.
  • Improper suppression: Suppression rules applied broadly, without a specific customer identifier, matched list record, reviewer name, and sunset date, can mask genuine future matches.
  • Stale escalation paths: A procedure that names individuals who are no longer in the role, or routes to a function without authority, produces delay at exactly the point where speed is required.

Evidence to produce:

  • Written alert disposition procedure covering review steps, documentation standards, decision categories, and scenario test results
  • False-positive suppression policy with specificity requirements and sunset trigger
  • Escalation matrix with named functions, authority levels, and response time expectations

7. Run continuous monitoring across the full customer portfolio

Owner: Compliance or sanctions operations 

Review frequency: Triggered by each list update, with full portfolio review cadence documented in the monitoring policy

Screening at fixed points in the customer lifecycle leaves the program running on a schedule that does not align with sanctions lists.

Onboarding screening captures the risk that exists at the start of a relationship, but designations arrive after accounts open. A counterparty that cleared every check at intake can appear on a watchlist weeks or months later, with no alert generated until the next scheduled review.

Without continuous monitoring, this interval is undetected exposure. Continuous monitoring rescreens the full portfolio each time a list updates, so the check runs on the list’s schedule rather than the program’s.

Adverse media monitoring catches risk signals that watchlist screening misses. Sanctions designations are a regulatory response to risk that often appears in public reporting well before formal action is taken, and a program without adverse media coverage has no visibility into that period.

Evidence to produce:

  • Written monitoring policy covering rescreening cadence, escalation procedures, and alert documentation standards
  • Log of monitoring runs with timestamps, list versions queried, and alert counts generated
  • Adverse media monitoring integration documented as a pre-designation control layer

Read more: Treasury’s Iran sanctions highlight new center of gravity in compliance: networks, not names

8. Maintain reporting records and retention documentation

Owner: Compliance or legal 

Review frequency: Annually, with immediate review triggered by any blocked transaction or potential violation

Reporting obligations attached to a sanctions violation are specific, dated, and independent of the screening program. A team that has never mapped these requirements before a violation occurs will be building the process under enforcement pressure.

OFAC’s reporting and retention framework covers four distinct requirements, each with a fixed deadline and a specific trigger.

 

Reporting obligation Trigger Deadline Administering authority
Blocking report Transaction blocked involving a designated party Within 10 business days of the blocking action OFAC
Annual report of blocked property Holding blocked assets at any point during the calendar year September 30 each year OFAC
Voluntary self-disclosure Potential violation identified before OFAC opens a formal investigation As soon as practicable, with earlier submission strengthening mitigation OFAC
Recordkeeping retention All transactions subject to a sanctions program Ten years from the date of the transaction OFAC (aligned with statute of limitations updated March 2025)

 

Voluntary self-disclosure is the most consequential of the four. A qualifying submission, filed through OFAC’s online VSD portal before a formal investigation opens, can reduce the base civil penalty by up to 50%.

OFAC’s ten-year recordkeeping requirement, effective March 2025, extends the window in which every transaction subject to a sanctions program must be documented. Anything reconstructed after the fact carries less weight with regulators.

Evidence to produce:

  • Blocking report template and documented submission process (10-business-day deadline)
  • Annual blocked property report filing log
  • VSD protocol with decision criteria, drafting process, and legal sign-off procedure
  • Retention policy stating the ten-year documentation window and the storage location for each record type

Read more: OFAC screening software: best practices for faster, more accurate sanctions compliance

Who owns each control in a sanctions screening program

How Sigma360 supports a defensible sanctions screening program

Sigma360 Homepage

Sigma360 is built around the evidence requirements each of the eight control areas demands:

  • Multi-regime list coverage with verified refresh: Every list update is confirmed, logged, and timestamped, so the ingestion assurance record that regulators and banking partners expect is produced automatically.
  • Ownership chain mapping: Entity resolution reaches the structures behind the customer name, including beneficial owners, nominee directors, and layered holding arrangements, producing a scope of screening that goes beyond what any published watchlist captures.
  • AI-assisted alert triage with case-specific documentation: The AI Investigator Agent scores and documents each alert before it reaches a reviewer, with every decision logged at the required level of specificity, covering customer, list entry, reviewer, date, and rationale.
  • Continuous monitoring with a pre-designation signal layer: Perpetual KYC keeps every relationship under active review at each list update, while adverse media screening picks up risk signals before regulators have acted on them.
  • Audit-ready decision trails: Every screening event, alert, analyst action, and outcome is preserved at the point of decision, with AML investigation workflows that export structured summaries ready for regulatory examination or VSD submissions.

Use the checklist to identify where your program stands, then speak to a compliance expert to see how Sigma360 addresses the controls that need strengthening, or explore sanctions and watchlist screening to review the full platform capability.

FAQ

What is the difference between sanctions screening and AML screening?

Sanctions screening checks whether a party appears on a government watchlist, with a confirmed match triggering a block or enhanced review. 

AML screening is a broader control that checks customers against risk indicators including PEPs, adverse media, and high-risk classifications, each operating under a different regulatory framework.

What is the difference between sanctions screening and sanctions monitoring?

Screening is a point-in-time check at onboarding or payment initiation. Monitoring rescreens existing relationships each time a list updates, catching designations that arrive after the initial check.

What triggers a sanctions screening review?

Business changes are the most common trigger, including a new product, geography, payment corridor, or correspondent relationship. Regulatory audits, failed list refreshes, and major new enforcement actions also prompt reviews.

Does sanctions screening apply to businesses that are not banks?

Yes. OFAC’s jurisdiction extends to all US persons and entities regardless of industry, and many non-bank businesses carry screening obligations under one or more sanctions regimes. The specific requirements depend on the business model, the jurisdictions it operates in, and the payment rails it uses.

How long does it take to implement a sanctions screening program?

A basic screening setup can be live in a few weeks. A fully documented program covering list coverage, threshold settings, alert procedures, and ingestion controls generally takes two to three months to build out properly.

About Sigma360 | The Standard in KYC & Financial Crime Compliance

Sigma360 is an AI-powered, full-stack risk intelligence platform that consolidates operations into one enterprise-grade system, enabling point-in-time risk screening and perpetual client monitoring for financial crime prevention and compliance operations. Sigma360 unifies global risk data, proprietary intelligence, core screening technology and AI automation in a secure cloud environment to find direct and network-based risks at sub-second speed, reduce false positives and strengthen risk and compliance operations.

Sigma360.com / Schedule a Demo / Free Trial / Connect on LinkedIn

Engage with us

Our Risk Intelligence Specialists can get you the answers you need.