Sanctions screening (OFAC, OFSI, EU, UN)
Sanctions screening is the process of checking customers, beneficial owners, and transactions against official sanctions lists to ensure the operator does not deal with designated persons or entities. The main regimes are OFAC (United States), OFSI (United Kingdom), the EU consolidated list (EU member states), and the UN Security Council Consolidated List (binding on all UN members). Sanctions compliance is legally distinct from AML risk-rating: it is not risk-based or discretionary but a strict-liability prohibition, so a confirmed match must be frozen/blocked and reported even if the customer would otherwise score as low risk. Screening must happen at onboarding and continuously thereafter, because lists change frequently.
Key list owners: OFAC (US Treasury, SDN and other lists), OFSI (UK, consolidated list), the EU consolidated financial sanctions list, and the UN Security Council Consolidated List.
Sanctions breaches are strict liability: in the US, OFAC can penalise a prohibited dealing with no proof of knowledge or intent; in the UK, OFSI can impose civil monetary penalties on a strict-liability basis (since 15 June 2022).
This is why sanctions screening is separate from AML risk-rating: you cannot 'risk-accept' a sanctioned party, and a positive match blocks the relationship outright rather than triggering enhanced monitoring.
Screening is required both at onboarding and on an ongoing basis, including re-screening the customer base whenever lists are updated, because designations can be added at any time.
UK maximum civil penalty (OFSI) is the greater of £1 million or 50% of the value of the breach; US IEEPA civil maximum is the greater of about USD 377,700 or twice the transaction value, adjusted annually for inflation.
Effective screening depends on data quality and fuzzy/alias matching (spelling variants, transliteration, dates of birth) to avoid missing near-matches.
Gambling and iGaming operators must screen every customer (and often beneficial owners and payment counterparties) against the relevant OFAC, OFSI, EU, and UN lists at onboarding and re-screen continuously as lists change, and any confirmed hit must be frozen and reported rather than played through. Because the operator's exposure depends on its licence jurisdiction and payment flows, cross-border operators frequently have to apply more than one regime at once, and a single missed designation can trigger strict-liability penalties independent of any AML failing.
Reference, not advice. This is a teaching summary of the AML framework — not legal advice, and not an operational compliance procedure. Confirm requirements against the primary regulator and your own counsel.