1 Obligations under the regulations
All UK persons must comply with UK financial sanctions. It is a criminal offence to breach them without a valid OFSI licence. OFSI, in HM Treasury, maintains the Consolidated List of financial sanctions targets. The FCA does not enforce the asset freeze itself — it expects the firms it supervises to have adequate systems and controls so that a freeze is not missed.
Firms subject to the financial-crime rules in SYSC 3.2.6R or SYSC 6.1.1R must have adequate systems and controls. FCA Financial Crime Guide chapter 7 says screening itself is not a legal requirement, but effective, up-to-date screening of customers, counterparties and payments against the Consolidated List — including rescreening when names are added — is how firms avoid a breach. An insurer that only screens when a claim is made is called out as poor practice.
If you know or have reasonable cause to suspect a breach, you must report it to OFSI. Consider a parallel notification to the FCA under Principle 11 and SUP 15.3 where the breach (or a near miss) points to a significant systems-and-controls failure. Sanctions screening is not the same as AML name screening — FCG 7 is explicit that standard AML checks do not replace a Consolidated List check.
2 What do I need to do
Write down who you screen, against which lists, and when. Then run that policy at take-on, on list change, and before value leaves the firm.
1. Define the screening population and the lists
Customers, directors, beneficial owners, counterparties, payees and, where relevant, beneficiaries. The UK Consolidated List is the baseline. Include directors and beneficial owners — FCG 7 expects that breadth. Regzact can assist: run UK and EU sanctions searches in bulk from files or APIs.
2. Screen at customer take-on — not only at claims
Screen new customers before you provide services. Rescreen existing customers when the Consolidated List is updated, and before claims and other payments. Update your screening lists on a service level that matches your sanctions risk. Regzact can assist: record each search against the customer or partner profile and alert owners when a review is due.
3. Calibrate matching and triage every alert
FCG 7 expects fuzzy matching (variant spellings, name reversal, character manipulation). That creates false positives — which you must discount with a recorded reason, not ignore. Regzact can assist: use AI to filter false positives so analysts spend time on genuine matches.
4. Freeze, stop the payment, and report
A true match: do not deal, freeze funds or economic resources, and notify OFSI. Escalate internally and consider an FCA notification if controls failed. Regzact can assist: generate tasks, send alerts, and keep the case and evidence on an auditable register.
3 What records do I need to keep
FCG 7 asks whether you have a clear policy on who and what is screened, how quickly lists are updated, and how alerts are governed. Your records should answer those questions.
- Screening policy: population, lists, frequency, matching rules and who may discount an alert
- Each screen: who, which list version, date and time, and the result
- Alert decisions with reasons — including discounted false positives
- Freeze and payment-block actions, and any OFSI licence relied on
- Reports to OFSI and, where relevant, the FCA
- Testing of the screening tool and sample quality-assurance of discounted alerts
- Training for staff who clear alerts
4 Using AI to streamline the process
Fuzzy matching is required to catch variants — and it generates noise. That is the right place for AI, with a human still owning the true-match decision.
- Rank alerts so obvious non-matches are cleared faster
- Explain why two names look similar but are probably different people
- Find customers or payees never screened, or not screened since a list update
- Draft the internal escalation and OFSI notification pack for a potential true match
Do not auto-close a possible true match. Use AI to weed out false positives; keep freeze-and-report decisions with the sanctions officer.
5 How Regzact can help
Regzact’s sanctions screening supports UK and EU lists, bulk search, and an AI filter for false positives.
- Screen customers and counterparties from files or APIs
- AI-assisted triage so analysts are not clearing obvious non-matches by hand
- Evidence of each search on the customer or partner profile
- Tasks, alerts and management reporting on outstanding alerts and true matches
SM&CR records, partner profiles, error registers and data-request files sit on the same platform if a hit overlaps with another event. Regzact can assist with each step of this process.
This is a practical how-to for compliance managers. It is not legal advice. Always check the current text of the regulations and your own policies before you act.