Practical guide
Sanctions screening policy: scope, review, and monitoring checklist
Define a sanctions screening policy with named sources, input standards, review authority, exceptions, monitoring triggers, evidence, and control testing.
On this page
Write a policy the team can execute
A screening policy should connect the organization’s obligations and risk assessment to concrete actions. OFAC’s jurisdiction guidance and applicable program rules inform the legal scope. The organization then needs operational choices that fit its actual customers, activities, and systems.
This checklist is not a universal legal template. It identifies the decisions a team needs to make and document with appropriate compliance and legal input.
Define parties, sources, and checkpoints
Identify which relationship roles are screened and why. Specify the required sources or governed packages, supported entity types, acceptable input quality, and relevant screening events. Keep ownership and non-list controls separate.
A policy should state whether a changed legal entity, corrected identifier, new payee, or source update triggers a new check. “Screen at onboarding” is incomplete when the relationship can materially change later.
Define outcomes and reviewer authority
Specify the path for a completed potential match, completed no match, and incomplete check. Establish the evidence standard for confirmation or dismissal and identify who can make the separate business action. Require independent review where the organization’s policy calls for it.
Missing source data or an unavailable service must not silently reduce required coverage. Define an exception process with an owner, approval, limits, and follow-up.
Make monitoring and evidence operational
Define the monitored population, cadence, event triggers, subject-update process, pause or closure rules, and who handles failures. Recordkeeping should identify records, access, retention triggers, legal holds, approved repositories, and deletion procedures.
The monitoring guide helps distinguish cadence from source freshness. The recordkeeping guide explains why current rules must be checked before copying an old retention period.
Use a policy decision worksheet
Complete this worksheet with actual owners and approved decisions. It is an internal planning aid, not an API payload or a regulator-issued form.
Screening policy worksheet
Business activities and jurisdictions in scope
Relationship roles and legal entities to identify
Required sources and coverage owner
Input standards and correction process
Screening checkpoints and monitoring triggers
Potential-match review standard and authorized reviewers
Independent review requirements
Incomplete-check and unavailable-source procedure
Legal escalation and business disposition authority
Evidence repositories, retention triggers, and access
Testing population, metrics, and change approval
Policy owner, approval date, and next review triggerTest before and after a material change
Test candidate discovery, identity review, source failures, monitoring recovery, and evidence retrieval. Review the effect of a new source or matching-policy change before rolling it across the full customer population.
SanctionsKit policies documentation explains the product’s versioned policy model. A configured policy is one implementation of the written process, not a substitute for deciding what the process should be.
Official references
- OFAC FAQ 11: who must comply (opens in a new tab)
- OFAC FAQ 5: assessing a possible match (opens in a new tab)
- 31 CFR 501.601: records and recordkeeping requirements (opens in a new tab)
- SanctionsKit: published OpenAPI contract (opens in a new tab)
- OFAC: final rule extending certain recordkeeping requirements (opens in a new tab)