Practical guide
Sanctions screening for small businesses: a workable process
Build a manageable sanctions screening process for a small business, with clear party selection, review ownership, evidence, and escalation boundaries.
On this page
Begin with the business activity and responsibility
A small team still needs to understand applicable sanctions obligations. OFAC FAQ 11 describes the general persons within scope; company size is not, by itself, an exemption. The appropriate control depends on the activity, jurisdiction, counterparties, and risk.
The aim is a process the team can actually operate. Avoid buying a tool before deciding who will handle a potential match, who can answer a legal question, and where evidence will be kept.
Write down a small number of clear checkpoints
Choose the business events at which screening matters, such as adding a supplier or onboarding a customer. Identify the legal party rather than only a brand or contact name. Document the required sources and the information staff should collect through an approved process.
A short written policy is more useful than an informal expectation that somebody searches the name occasionally. State what happens when required information or source coverage is unavailable.
Give uncertain results a real owner
A possible match needs comparison of the actual source record and reliable customer details. The person making a sale should know how to refer the case without deciding identity from a score. Use the false-positive checklist for an evidence-based comparison.
Where staffing is limited, define when external compliance or legal advice is required. Do not relabel an unresolved case as dismissed simply because there is no second analyst on shift.
Keep evidence in a controlled place
Retain the screening reference, coverage, source context, reviewer reasoning, and separate business decision under the approved policy. Keep sensitive original documents in an appropriate repository with restricted access.
SanctionsKit can hold retained screening evidence and approved external document references. It does not turn an emailed identity document into securely governed evidence just because an employee pasted a link into a comment.
Plan costs around the relationship, not the first check
Estimate initial checks, occasional corrections, required periodic reviews, and monitoring rescreens. Start with a representative sample to understand likely review effort. Use current plans and pricing, not a generic promise of unlimited screening.
A low request price is not enough if staff cannot investigate the results or retrieve the record later. Compare operational effort, evidence quality, and integration needs alongside price.
Test the process with invented examples
Before launch, use a synthetic no-match case, a similar-name candidate, a missing-date case, and a failed check. Ask the responsible person to explain the next action and locate the evidence. Fix unclear steps before using real customer data.
Review the process when the business adds a market, changes its service, or starts using new sources. This guide is an operational starting point, not a legal determination of which obligations apply.