IndiciumIndicium
Log in
← Back to blog
Background checks for HR, Legal and Compliance

Turn public-source risk signals into audit-ready decisions.

Indicium helps regulated teams screen candidates, counterparties and sensitive hires — with dated sources, human review and reports your Legal team can defend.

sanctions-screening

Sanctions screening: EU vs OFAC vs UN lists explained

Understand the differences between EU, OFAC, and UN sanctions lists, when each applies, and how to build a defensible screening process for KYC/AML compliance.

Sanctions screening is not optional. Whether you are a bank onboarding a corporate client, an executive search firm placing a CFO, or a family office vetting a new advisor, you need to know which lists to check, when each applies, and how to document that you did it properly.

The problem: there is no single “sanctions list.” There are at least three major regimes — the European Union, the US Office of Foreign Assets Control (OFAC), and the United Nations Security Council — plus national lists like SECO in Switzerland. Each has different scopes, different legal bases, and different consequences for missing a match.

This guide explains the differences, when each list matters, and how to build a screening process that holds up in an audit.

The three major sanctions regimes

European Union (EU)

Legal basis: Common Foreign and Security Policy (CFSP), implemented through Council Regulations.

Scope: Applies to all EU persons and entities, and to anyone doing business in the EU. This includes EU subsidiaries of non-EU companies.

Lists: The EU maintains consolidated lists of persons, groups, and entities subject to financial sanctions. These include asset freezes, travel bans, and arms embargoes.

Key point: If you are an EU entity or have EU operations, EU sanctions are mandatory. The lists are updated frequently — sometimes daily — and you are expected to screen against the current version.

US OFAC

Legal basis: US sanctions programs under the International Emergency Economic Powers Act (IEEPA), Trading with the Enemy Act (TWEA), and other statutes.

Scope: Applies to US persons, entities organized under US law, and — critically — to transactions with a US nexus. This includes USD clearing, US-origin goods, and US financial institutions.

Lists: OFAC maintains the Specially Designated Nationals (SDN) list, the Consolidated Sanctions List, and various program-specific lists (e.g., Iran, Russia, North Korea).

Key point: OFAC has extraterritorial reach. A German bank processing USD payments for a Swiss client can face US enforcement action if the client is on the SDN list. This is why many non-US companies screen OFAC even when not legally required.

United Nations Security Council

Legal basis: UN Charter Chapter VII, implemented through Security Council Resolutions.

Scope: UN sanctions are binding on all UN member states. Each member state implements them through national legislation.

Lists: The UN Security Council Consolidated List covers all active sanctions regimes (e.g., ISIL/Al-Qaida, Taliban, DPRK, Libya).

Key point: UN sanctions are the baseline. If someone is on the UN list, they are effectively sanctioned everywhere. However, the UN list is narrower than EU or OFAC lists — many EU and US designations go beyond UN requirements.

When does each list apply?

Situation EU OFAC UN
EU bank onboarding a corporate client Required Recommended (if USD involved) Required
Swiss executive search placing a CFO in Germany Required Recommended Required
US private equity fund acquiring a German company Required Required Required
Family office in Zurich vetting a new advisor Recommended Recommended Required
German manufacturer exporting to Turkey Required Required (if USD or US goods) Required

The practical rule: screen EU + OFAC + UN for any cross-border business. Add SECO for Swiss nexus. Add national lists (e.g., UK OFSI, French Tracfin) if you have specific jurisdictional exposure.

How to build a defensible screening process

1. Screen at onboarding and periodically

One-time screening at onboarding is not enough. Sanctions lists change. A client who was clean in January may be designated in March. Best practice: screen at onboarding, then re-screen quarterly or when there is a trigger event (new beneficial owner, new jurisdiction, adverse media hit).

2. Use fuzzy matching, not exact matching

Names are transliterated differently. “Mohammed” vs “Muhammad” vs “Mohamed.” A good screening tool uses fuzzy matching algorithms to catch variants. But fuzzy matching creates false positives. You need a documented process for resolving them.

3. Document every decision

When you get a potential match, you must document: what the match was, why you concluded it was a false positive (or true match), who made the decision, and when. This documentation is what regulators ask for.

4. Screen beneficial owners, not just the entity

If you are onboarding a company, you must screen its beneficial owners (typically anyone with 25%+ ownership or control). A clean company with a sanctioned UBO is a sanctions violation.

5. Have an escalation process

What happens when you get a true match? Who decides whether to exit the relationship? What do you tell the client? These decisions must be documented and consistent.

Common mistakes

  • Screening only the entity, not the UBOs: This is the most common gap. Regulators expect UBO screening.
  • Using stale lists: Sanctions lists change daily. Using a list from last month is a compliance failure.
  • No false positive documentation: “It was a false positive” is not enough. You need to show your reasoning.
  • Ignoring OFAC because “we are not a US company”: If you touch USD, US goods, or US financial institutions, OFAC applies.
  • No periodic re-screening: Onboarding-only screening misses designations that happen after onboarding.

What a defensible report looks like

A defensible sanctions screening report includes:

  • The lists screened (EU, OFAC, UN, SECO, others)
  • The date of the list versions used
  • The search terms and matching logic
  • All potential matches identified
  • The resolution of each match (false positive / true match / escalated)
  • The name of the person who made the final decision
  • The date of the decision

This is what auditors and regulators expect. Not a screenshot of a database query — a documented decision trail.

Bottom line

Sanctions screening is complex because there is no single list. EU, OFAC, and UN each have different scopes and legal bases. The practical approach: screen all three, document everything, re-screen periodically, and have a clear escalation process for true matches.

The cost of getting it wrong: fines, reputational damage, and in some cases criminal liability. The cost of doing it right: a documented process that takes minutes per case and holds up in any audit.

This article provides general information and does not constitute legal advice. For specific compliance questions, consult qualified legal counsel.

Ready to move from reading to doing?

See how a reviewable risk report is built — from name to verdict in minutes, not weeks.

Book a demo See a sample report