Practical guide

How often should customers be screened against sanctions lists?

Set a risk-based sanctions rescreening policy using relationship events, source changes, monitoring cadence, and evidence of successful checks.

On this page

There is no useful one-size-fits-all product answer

Screening frequency should follow the organization’s obligations, risk assessment, relationships, and activities. Do not infer a universal daily, annual, or per-transaction legal rule from a vendor’s default schedule. Bank-specific FFIEC OFAC guidance should be read in its institutional context.

A policy needs both recurring checks and event triggers. An annual review date does not address a material identity change the day after onboarding.

Identify the events that change the question

Common design triggers include a new relationship, changed legal identity, corrected identifier, different transaction party, relevant ownership information, a source update, and a policy change. Decide which are relevant to the business and who initiates the new check.

Keep the reason for the rescreen with its result. A changed customer record, a changed source, and a periodic check may produce the same candidate while answering different operational questions.

Distinguish cadence from source freshness

A six-hour schedule describes when the customer is checked, not how quickly an authority publishes or a provider ingests data. A daily check against stale coverage is still stale. Conversely, fresh coverage does not help an inactive monitor that never completes a run.

Record the source version and successful completion time. Use the freshness guide to separate publication, ingestion, activation, and screening times.

Choose a cadence the team can support

Consider the relationship’s duration, activity, exposure, and the consequence of delayed review. Estimate screening volume and analyst workload. SanctionsKit’s documented schedules are six-hour, daily, and weekly, with qualifying source-triggered full rescreens as well.

The selected cadence should not exceed the organization’s ability to handle the resulting issues. A queue nobody reviews does not become a strong control merely because rescreens run frequently.

Document the decision and exceptions

For each monitored population, record its source coverage, cadence, event triggers, input owner, reviewer, failure escalation, and stop conditions. State how unavailable sources and overdue checks are detected.

For an invented supplier population, the team chooses a recurring cadence and also requires a new check when the contracting entity changes. The second rule matters even if the next periodic run is not yet due. This is an operational illustration, not a prescribed legal interval.

Review whether checks actually complete

Sample the monitored population and compare expected runs with successful results. Investigate repeated failures, stale inputs, paused records, and unresolved alerts. Reassess the policy when markets, sources, products, or obligations change.

Keep the monitoring workflow connected to case review. A completed rescreen produces evidence; the organization still needs to decide what to do with it.

Official references