What is sanctions screening?
A practical guide to list-based sanctions checks for CDD teams — who typically must do them, how matching works, and what to do on a hit.
What sanctions screening is
Sanctions screening is the practice of checking whether a person, company, vessel, or other entity appears on government or international lists that restrict dealing with them. Those lists exist to freeze assets, block transactions, or limit trade with designated parties — for example targets of United Nations, United States, European Union, United Kingdom, or other national sanctions regimes.
In customer due diligence (CDD) and know-your-customer (KYC) workflows, screening is usually an early step: before you open a relationship or complete a transaction, you ask whether the name you have is associated with a prohibitive listing. A hit does not automatically prove identity — it is a signal to investigate further.
Who typically must screen
Obligations vary by jurisdiction and licence type. In Hong Kong, anti-money laundering rules under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (AMLO) require many financial institutions and designated non-financial businesses and professions (DNFBPs) — including trust or company service providers (TCSPs) — to perform CDD and to be alert to sanctions and terrorist-financing risks.
Even where a specific statute does not name “sanctions screening” as a standalone duty, firms often screen as a practical control: banks, remittance houses, company secretaries, accountants, lawyers, and corporate service providers routinely check names against open and commercial lists before onboarding.
How list-based screening works
Modern screening compares the names you supply against a consolidated dataset built from many source lists. Open datasets such as OpenSanctions aggregate sanctions designations, wanted notices, and debarment or exclusion lists so a single search can cover a wide range of jurisdictions.
Matching is rarely a simple string equality check. Names are normalised (Unicode forms, punctuation, honorifics), then compared with exact and fuzzy techniques for Latin scripts, and with script-appropriate rules for Chinese and other CJK names. Tools typically return candidate matches with a similarity score so a human — or a fixed rule engine — can decide which hits are strong enough to matter.
Fuzzy matching pitfalls
False positives are common: common surnames, transliteration variants, and abbreviated company names can look similar to sanctioned parties. False negatives happen when the subject uses an alias, a different script, a maiden name, or a trading name that is not on the list you searched.
A high similarity score is not proof of identity. Always compare dates of birth, nationalities, addresses, registration numbers, and other identifiers when they are available. Treat weak fuzzy matches as investigative leads, not as automatic blocks — and document why you cleared or escalated each material hit.
What to do when you get a hit
Pause the onboarding or transaction if your policy requires it. Confirm whether the match is strong enough and whether the list type is prohibitive (sanctions, crime, wanted, debarment) versus informational. Corroborate with independent sources — official list pages, corporate registries, news of record — before you freeze a relationship or file a report.
Keep a clear audit trail: who was screened, when, which dataset version, what matched, and what decision you made. Automated tools can produce a PDF snapshot for the file; they do not replace your firm’s escalation procedures or legal advice.