Resources · United Kingdom
United Kingdom · Financial sanctions

How to run sanctions searches

When to screen customers, counterparties and payments against the UK Consolidated List, what to do with a match, and how to keep the evidence.

1 Obligations under the regulations

All UK persons must comply with UK financial sanctions. It is a criminal offence to breach them without a valid OFSI licence. OFSI, in HM Treasury, maintains the Consolidated List of financial sanctions targets. The FCA does not enforce the asset freeze itself — it expects the firms it supervises to have adequate systems and controls so that a freeze is not missed.

SYSC 3.2.6R / SYSC 6.1.1R · FCG 7 · OFSI

Firms subject to the financial-crime rules in SYSC 3.2.6R or SYSC 6.1.1R must have adequate systems and controls. FCA Financial Crime Guide chapter 7 says screening itself is not a legal requirement, but effective, up-to-date screening of customers, counterparties and payments against the Consolidated List — including rescreening when names are added — is how firms avoid a breach. An insurer that only screens when a claim is made is called out as poor practice.

If you know or have reasonable cause to suspect a breach, you must report it to OFSI. Consider a parallel notification to the FCA under Principle 11 and SUP 15.3 where the breach (or a near miss) points to a significant systems-and-controls failure. Sanctions screening is not the same as AML name screening — FCG 7 is explicit that standard AML checks do not replace a Consolidated List check.

2 What do I need to do

Write down who you screen, against which lists, and when. Then run that policy at take-on, on list change, and before value leaves the firm.

1. Define the screening population and the lists

Customers, directors, beneficial owners, counterparties, payees and, where relevant, beneficiaries. The UK Consolidated List is the baseline. Include directors and beneficial owners — FCG 7 expects that breadth. Regzact can assist: run UK and EU sanctions searches in bulk from files or APIs.

2. Screen at customer take-on — not only at claims

Screen new customers before you provide services. Rescreen existing customers when the Consolidated List is updated, and before claims and other payments. Update your screening lists on a service level that matches your sanctions risk. Regzact can assist: record each search against the customer or partner profile and alert owners when a review is due.

3. Calibrate matching and triage every alert

FCG 7 expects fuzzy matching (variant spellings, name reversal, character manipulation). That creates false positives — which you must discount with a recorded reason, not ignore. Regzact can assist: use AI to filter false positives so analysts spend time on genuine matches.

4. Freeze, stop the payment, and report

A true match: do not deal, freeze funds or economic resources, and notify OFSI. Escalate internally and consider an FCA notification if controls failed. Regzact can assist: generate tasks, send alerts, and keep the case and evidence on an auditable register.

3 What records do I need to keep

FCG 7 asks whether you have a clear policy on who and what is screened, how quickly lists are updated, and how alerts are governed. Your records should answer those questions.

  • Screening policy: population, lists, frequency, matching rules and who may discount an alert
  • Each screen: who, which list version, date and time, and the result
  • Alert decisions with reasons — including discounted false positives
  • Freeze and payment-block actions, and any OFSI licence relied on
  • Reports to OFSI and, where relevant, the FCA
  • Testing of the screening tool and sample quality-assurance of discounted alerts
  • Training for staff who clear alerts

4 Using AI to streamline the process

Fuzzy matching is required to catch variants — and it generates noise. That is the right place for AI, with a human still owning the true-match decision.

  • Rank alerts so obvious non-matches are cleared faster
  • Explain why two names look similar but are probably different people
  • Find customers or payees never screened, or not screened since a list update
  • Draft the internal escalation and OFSI notification pack for a potential true match

Do not auto-close a possible true match. Use AI to weed out false positives; keep freeze-and-report decisions with the sanctions officer.

5 How Regzact can help

Regzact’s sanctions screening supports UK and EU lists, bulk search, and an AI filter for false positives.

  • Screen customers and counterparties from files or APIs
  • AI-assisted triage so analysts are not clearing obvious non-matches by hand
  • Evidence of each search on the customer or partner profile
  • Tasks, alerts and management reporting on outstanding alerts and true matches

SM&CR records, partner profiles, error registers and data-request files sit on the same platform if a hit overlaps with another event. Regzact can assist with each step of this process.

Open the Consumers solution · Book a demo

This is a practical how-to for compliance managers. It is not legal advice. Always check the current text of the regulations and your own policies before you act.

Keep going

Other how-tos for United Kingdom compliance teams.

Start Your Trial Today.

Join insurers, MGAs, and brokers across the UK and Ireland who have made compliance a strategic advantage. Book a personalised demo and see Regzact working with your own network.

No credit card required All regulatory frameworks included Set up in under a day

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.