Sanctions Screening Checklist Template

A new designation can land at any hour, and liability does not wait for your next batch run. When alerts are cleared without a reason or a true match sits in a queue, the screening tool did its job and the process around it failed.

Sanctions screening checks customers, their owners and controllers, and payments against government lists of designated persons. This free checklist is for sanctions and financial crime teams at banks, payment and e-money firms, brokers, wealth managers and fintechs subject to US (OFAC), UK (OFSI) or EU sanctions. It runs one screening cycle from list update to closure: loading the lists, re-screening, triaging alerts, testing ownership and control, freezing or rejecting on a true match, reporting to each regulator on time and keeping the records. Ownership analysis, true-match handling and the monthly QA review only appear when the answers call for them.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: October 2026

Sanctions Screening, AML Monitoring and KYC: Related, Not the Same

Sanctions screening is usually run by the financial crime team alongside anti-money laundering controls, but the legal test is different. Money laundering rules turn on suspicion and require a report. Sanctions rules turn on who the person is and who owns them, and they require you to stop. OFAC civil penalties are strict liability, and since 15 June 2022 OFSI can also impose civil penalties without proving that a firm knew or suspected it was breaching sanctions.

That makes timing the core risk. Lists change without notice, and a customer who was clean at onboarding can be designated on a Tuesday afternoon. A firm needs to know which list version it screened against, how quickly it re-screened after an update, and why each alert was closed.

KYC and CDD

Who is the customer?

Test: identity, ownership and purpose of the relationship.

Timing: at onboarding and periodic or trigger reviews.

Output: a verified file and a risk rating.

AML monitoring

Is the activity suspicious?

Test: behaviour against the customer’s profile.

Timing: ongoing, with alerts investigated.

Output: a closed alert or a suspicious activity report.

Sanctions screening

Is a designated person involved?

Test: names, owners and payment parties against official lists.

Timing: onboarding, every list update, every payment.

Output: a cleared alert, or a freeze, block or reject and a report.

What the Sanctions Screening Checklist Covers

Three phases run on every cycle. Ownership and control, true-match handling, regulator reporting and the monthly QA review switch on only when the answers in earlier phases call for them.

Phase 1

Phase 1: Load the Lists & Run the Screen

Assigned to the sanctions analyst on duty. The match answers recorded in Phase 2 decide which freeze and reporting tasks appear later.

  • Record the run type — list update re-screen, onboarding batch, periodic full re-screen or payment alert
  • Record the regimes in scope — OFAC, UK, EU and UN, from the firm’s sanctions policy
  • Confirm each list version and when it was loaded — OFAC SDN and non-SDN lists, the UK Sanctions List, the EU consolidated list, the UN list
  • Record the delay between publication and screening — measured against the firm’s target, so slow loads show up
  • Confirm the screened population is complete — customers, beneficial owners, directors, signatories and counterparties reconcile to the source systems
  • Record the number of alerts generated — and attach the screening report
Phase 2

Phase 2: Alert Triage & Disposition

  • Compare each alert with the list entry’s identifiers — date of birth, nationality, address, registration number, vessel or aircraft details
  • Close false positives with a written reason — “name match only” is not a reason; cite the identifier that differs
  • Escalate potential matches to a second-level reviewer — any alert that cannot be ruled out on the data held
  • Hold any related payment while a potential match is open — release only once it is cleared
  • Record whether any alert involves an owner or controller of an entity — a Yes opens the ownership and control phase
  • Record whether there is a confirmed or unresolved true match — a Yes opens the true-match and reporting phases
Phase 3 — Ownership Alerts Only

Phase 3: Ownership & Control Assessment

Shown only when an alert involves a designated person in an entity’s ownership or control chain.

  • Map the ownership chain with evidence — registry extracts, shareholder registers and the KYC file, at every level
  • US: apply the OFAC 50 Percent Rule — blocked persons owning 50% or more in aggregate, directly or indirectly, make the entity blocked
  • EU: apply 50% or more ownership with holdings of designated persons aggregated — then the control criteria in the EU Best Practices
  • UK: test ownership of more than 50% of shares or voting rights — then the right to appoint a board majority, and the control test
  • Look for control without ownership — directors, nominees and side agreements; OFAC’s rule is ownership-based but control still carries risk
  • Record the conclusion for each regime — treated as designated or not, with the evidence attached
Phase 4 — True Match Only

Phase 4: Freeze, Block or Reject

Shown only when a true match is confirmed or cannot be ruled out. The decision is an approval task for the nominated sanctions officer.

  • Stop the transaction or freeze the account immediately — no further dealing while the decision is made
  • US: decide block or reject — property in which a blocked person has an interest is blocked; other prohibited transactions are rejected
  • US: move blocked funds into a separate blocked, interest-bearing account — as the OFAC programme regulations require
  • Consider whether a licence would allow any payment — general licences first, then a specific licence application
  • Sanctions officer approval of the disposition — Approved, or Not approved and returned with reasons
  • Refer to the MLRO or BSA officer where there is also suspicion — a suspicious activity report may be needed as well
Phase 5 — True Match Only

Phase 5: Report to Regulators

Tasks appear for the regime of the confirmed match, with due dates set from the date of the action.

  • OFAC: file the blocked property report within 10 business days — through the OFAC Reporting System
  • OFAC: file the rejected transaction report within 10 business days — for each transaction rejected
  • OFAC: add the property to the Annual Report of Blocked Property — holdings as at 30 June, due by 30 September
  • UK: report to OFSI as soon as practicable — the designated person, what the firm holds and how the knowledge or suspicion arose
  • UK: include frozen assets in OFSI’s annual frozen assets review — the 2026 deadline is 30 November
  • EU: report to the national competent authority — within two weeks under the Russia regime, Regulation 269/2014, Article 8
Phase 6

Phase 6: Records & Case Closure

  • Attach the alert decisions and evidence to the cycle record — list version, identifiers compared, reviewer and outcome
  • Update the customer file and risk rating — a close match or an ownership finding can change the KYC view
  • Add confirmed false positives to the good-guy list with an expiry — so they are tested again on the next list change
  • Apply the retention period — 10 years for OFAC records; for UK and EU, the firm’s policy, at least the five-year AML minimum
  • Close the cycle and record the time from list publication to final disposition — the number examiners and auditors ask for
Phase 7 — Monthly Run Only

Phase 7: QA, Tuning & MI

Shown on the first cycle of each month. The QA checker must not have dispositioned the alerts being sampled.

  • Four-eyes QA on a sample of closed alerts — was the reason valid and the evidence attached?
  • Run a test file of known designated names through the screening tool — to confirm it still catches them after any change
  • Review fuzzy-matching thresholds and rules — any change is documented and approved, not tuned to cut workload alone
  • Review list coverage and data quality — missing dates of birth, truncated names and unscreened fields
  • Report MI to the MLRO or sanctions committee — alert volumes, ageing, true matches, reports filed and QA failures

US, UK and EU Rules Side by Side

The three regimes overlap but differ on ownership, reporting deadlines and record keeping. Which apply to you depends on where you are, your customers and the currencies you handle, so treat the table as a starting point, not legal advice.

Requirement United States (OFAC) United Kingdom (OFSI) European Union Phase
ListsSDN List and non-SDN listsUK Sanctions List, the only source since 28 January 2026EU consolidated financial sanctions list1
Screening frequencyRisk-based, per OFAC’s 2019 compliance frameworkRisk-basedFrom 10 July 2027, regularly and on every new designation for financial institutions (AMLR Art. 26(4))1, 7
Ownership50% or more, aggregated, direct or indirect (50 Percent Rule)More than 50% of shares or votes, or board appointment rights50% or more, aggregated (Best Practices, July 2024)3
ControlNot part of the rule; treat with cautionControl test appliesControl criteria apply3
Action on a matchBlock, or reject a prohibited transactionFreeze; do not make funds availableFreeze; do not make funds available4
Report a matchBlocked and rejected reports within 10 business days, 31 CFR 501.603–604As soon as practicable, for relevant firmsTo the national competent authority; two weeks under Reg. 269/20145
Annual reportBlocked property as at 30 June, by 30 SeptemberFrozen assets review; 2026 deadline 30 NovemberNo EU-wide equivalent; check national rules5
Records10 years, since 21 March 2025 (31 CFR 501.601)No single sanctions period; AML records 5 yearsAML records 5 years6

Some of this is moving. In February 2026 the UK government opened a call for evidence on the ownership and control test, focused on the hypothetical element of control; it closed on 13 April 2026. The government has said it is exploring aggregation and a “50% or more” threshold to align with the US and EU, but at the time of writing the UK test is unchanged. OFSI also revised its enforcement guidance in February 2026, including an Early Account Scheme that can reduce a penalty for a firm that gives a full, early account of a breach. OFAC extended its record-keeping period from five to 10 years to match the longer statute of limitations enacted in April 2024, and has required electronic reporting through its reporting system since August 2024.

Why Run Sanctions Screening Cycles in CheckFlow?

1

Every list update gets a cycle

Open a cycle by hand, on a daily recurring schedule, or from your screening tool through the API and webhooks when a new list loads. Each cycle has an owner, and an unworked one shows as overdue.

2

Deadlines that start from the action

When Phase 2 records a true match, conditional logic opens the freeze and reporting phases for the regimes in scope, with the OFAC 10-business-day reports due from the date of the block or rejection.

3

A decision trail you can keep for 10 years

Screening reports, registry extracts and filed reports attach to their tasks. The sanctions officer’s decision is an approval task, and the timestamped activity trail exports for your record-keeping file.

CheckFlow is not a screening engine or list provider, and it does not match names or block payments. It runs the workflow around your screening tool: who loaded the list, who cleared each alert and why, who approved the freeze and when each report went in. CheckFlow’s compliance checklist software covers the rest of the financial crime calendar, and the fintech overview shows how payment firms run it.

Sanctions screening is one pillar of the wider programme reviewed in the AML Compliance Programme Review Checklist, where list update times and alert ageing feed the MLRO’s monthly pack. Re-screening at each KYC refresh follows the KYC Periodic Review Checklist, and new customers are screened at onboarding through the Customer Due Diligence Checklist.

Frequently Asked Questions

What is sanctions screening?

+

It is the process of checking customers, their beneficial owners and controllers, and the parties to payments against official lists of designated persons, such as OFAC’s SDN List, the UK Sanctions List and the EU consolidated list. Potential matches are investigated, false positives are closed with a reason, and true matches are frozen, blocked or rejected and reported.

How often should customers be re-screened against sanctions lists?

+

US and UK rules leave the frequency to a risk-based approach, but because liability does not depend on knowledge, most financial institutions re-screen the whole customer base whenever a list they apply changes, and screen payments in real time. From 10 July 2027 the EU AMLR requires financial institutions to check on every new designation as well as regularly.

What is the OFAC 50 Percent Rule, and how do the UK and EU tests differ?

+

Under OFAC’s rule, an entity owned 50% or more in aggregate, directly or indirectly, by one or more blocked persons is itself blocked, even if it is not on the list. Since July 2024 EU guidance also uses 50% or more with aggregation. The UK test is more than 50% of shares or voting rights or the right to appoint a board majority, plus a separate control test; aggregation and a 50% threshold are being considered but not adopted.

How quickly must a sanctions match be reported?

+

To OFAC, within 10 business days of blocking property or rejecting a transaction, through the OFAC Reporting System. To OFSI, as soon as practicable once a relevant firm knows or has reasonable cause to suspect it is dealing with a designated person. In the EU, reports go to the national competent authority; under the Russia regime the deadline is two weeks.

How long must sanctions records be kept?

+

For OFAC, at least 10 years after the transaction, and for blocked property 10 years after it is unblocked. The longer period applies from 21 March 2025. UK and EU sanctions rules set no single equivalent, so most firms keep screening records for at least their five-year AML record-keeping period, and many align with the US 10 years.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Clear Every Alert With a Reason and Every Report on Time

Free trial — no credit card required.