Corpenza
Get Started
Independent Audit and Compliance8 min

Sanctions Screening for Cross-Border Businesses: A Practical Customer Onboarding Flow

A practical customer-onboarding flow for recording sanctions risk, screening relevant parties, resolving potential matches and retaining an auditable decision record.

Berk Tüzel
Berk Tüzel
August 5, 2026
sanctions screeningcustomer onboardingcross-border compliance
Sanctions Screening for Cross-Border Businesses: A Practical Customer Onboarding Flow

Sanctions screening is more than entering a customer name into a list-search tool. The customer, signatory, beneficial owner, payment account, goods or services, delivery point and intermediaries need to be visible in the same transaction file. The point is not to produce a clean-looking result. It is to show what was checked, when it was checked, what evidence was used and why the business decided to proceed, pause or decline.

This is an operational starting flow, not legal advice for a particular sanctions regime. Applicable rules depend on the place of establishment, the parties, payment and financing channels, the origin of goods and the route. The European Commission states that EU sanctions bind EU nationals, persons located in the EU and people doing business there within EU jurisdiction. Transactions with a US nexus may also require an assessment against OFAC rules and guidance.

1. Define the scope before the deal moves

Start before contract signature or payment. Capture the legal name, registration number, country, business activity, signing authority, direct and indirect ownership, billing and delivery countries, and payment details. Compare the commercial record with the contract draft, corporate record and payment instruction. If those sources do not agree, document and resolve the gap before progressing.

Put a risk classification in the file as well. Geography, product or service, the customer's activity, intermediaries, payment pattern and unusual timing or routing affect the level of review. OFAC's framework describes a risk assessment that considers customers, supply chain, intermediaries, counterparties, products, services and geographic touchpoints. That is not an automatic approval rule. It is a recorded basis for deciding what additional checking is proportionate.

2. Make the screening record reproducible

Do not restrict screening to the legal entity. Use separate search records for beneficial owners, directors, signatories, known intermediaries and the payee of the account. For each record, retain the source used, search date and time, search term, possible-match outcome and reviewer. A similar name is neither a confirmed hit nor a clean result.

Record the official list source and the version or access date. OFAC's Sanctions List Service says it provides current SDN and consolidated non-SDN list data. For EU-scope activity, use the Commission's sanctions materials and the current text of the relevant measure. A list tool, a company registry and a customer declaration answer different questions. They should not be treated as substitutes for one another.

3. Separate a possible match from commercial pressure

A sales or operations team should not close a possible match with a short note saying "wrong person". Compare identifiers, country, date of birth or incorporation, address, ownership and transaction context. If uncertainty remains, pause the transaction and payment and escalate to the person responsible for compliance or legal review. The decision should identify the evidence used and the rule or rationale applied.

This separation helps manage commercial pressure. OFAC's framework identifies decentralised compliance, inconsistent application, lack of a formal escalation path and weak oversight as factors that can contribute to apparent violations. A simple rule may be enough for a smaller business: no contract execution or payment without compliance approval where there is a possible match, unclear ownership, a higher-risk route or a non-standard payment arrangement.

4. Do not close the file after approval

A screening decision needs an expiry point. A new owner, signatory, bank account, product, route or contract renewal can trigger a fresh review. Set rescreening frequency by risk class and name the owner of the task. The procedure should also state who can stop a transaction and who can seek external advice or contact a competent authority when the facts require it.

This flow does not replace advice on a specific regime. Recheck official update dates, the current legal text and relevant national competent-authority guidance at the time of the transaction. For a country-, product-, payment- and party-specific scope assessment, contact Corpenza.

Official sources

European Commission sanctions resources — page update shown as 17 November 2025; accessed 5 August 2026. OFAC Framework for Compliance Commitments — 2 May 2019; accessed 5 August 2026. OFAC Sanctions List Service — accessed 5 August 2026.

Frequently asked questions

Does a no-result list search mean the customer is risk-free?

No. A search is one control. Ownership, transaction route, product, payment and counterparty information still need review.

How long should we retain a screening result?

Retention follows applicable law, contract and internal policy. Keep the source, date, decision, responsible person and rescreening trigger in the file.

Start Your Global Growth Today

Let's reach your business goals together with 50+ expert consultants and partner networks in 9+ countries. First consultation is free.

Get Started