Understanding the Questions
Compliance officers at life insurers, P&C carriers, and reinsurance brokers often face urgent questions about sanctions screening. These queries arise when a claim adjuster needs to release a large payment quickly, a broker submits a new program with an unfamiliar counterparty, or finance flags a wire instruction involving multiple correspondent banks. The common thread is that sanctions risk often appears late in the contract lifecycle, precisely when speed is critical, and there's no time for lengthy policy memos.
The landscape shifted when the European Union adopted its twentieth package of Russia-related measures in April 2026. The UK's Financial Conduct Authority (FCA) published findings in May 2026, highlighting weaknesses in sanctions compliance, such as incomplete screening and slow alert handling. Your screening program must adapt without waiting for the next risk assessment cycle.
Screen Every Claim Payment, Not Just New Policies
You must screen every claim payment. A policyholder clear at underwriting can become designated between issuance and claim. The FCA's May 2026 findings specifically flagged incomplete screening at the payout stage as a control weakness.
Sanctions exposure in insurance spans the entire contract lifecycle, not just onboarding. A policy written today for a clean counterparty can face a designation tomorrow. The risk materializes when money moves, so claims, premium refunds, reinsurance settlements, and third-party payments all require screening. Screening only at issuance leaves gaps in subsequent transactions.
Operationally, your claims system should trigger screening before releasing funds, after claim approval but before the wire is sent. This isn't optional, and it can't be batched at month-end.
Understanding "Owned or Controlled" in Screening
"Owned or controlled" means you can't stop at the named counterparty. A party not on any sanctions list can still be restricted if a designated person owns or controls it. This requires examining corporate structures, not just screening the entity name on the policy or claim form.
For example, if you're paying a claim to a Cypriot holding company, you need to know who owns it. If a designated individual holds 50% or more, or if a designated person has decision-making authority, that entity is likely restricted even if its name isn't on the list.
Your Customer Due Diligence process and sanctions screening must connect. Beneficial ownership data collected during onboarding becomes critical for assessing control. Without current ownership information, you can't make a defensible screening decision.
Why OFAC Matters Even Without US Operations
Your payments likely clear through US correspondent banks. Secondary sanctions exposure doesn't require a US presence. If your cross-border payment involves a US financial institution, you've created potential OFAC exposure, even if your company is based in Frankfurt and the claim is paid to a policyholder in Singapore.
This is especially relevant for dollar-denominated transactions. Most USD payments route through New York, bringing OFAC rules into play. The same applies to reinsurance settlements and premium financing arrangements. If any part of the payment chain involves a US institution, you must consider US sanctions alongside EU and UK regimes.
Your screening logic must account for multiple jurisdictions, not just the regime where you're licensed. A transaction permissible under EU rules can still be blocked if it hits OFAC restrictions.
Aligning Sanctions Lists Across Entities
If your UK entity and EU subsidiary use different sanctions lists without a common source of truth, it's a problem. The EU, UK, and US align broadly on objectives but differ on details. The EU's twentieth Russia package in April 2026 extended listings and added new restriction categories, which don't always mirror UK or US measures.
The solution is centralized sanctions intelligence with configurable screening logic. A single function should monitor all relevant regimes and distribute current designations and guidance to every operating entity. Your screening platform must apply the correct rule set based on jurisdiction, transaction type, and payment route. A fixed rule set applied everywhere risks over-blocking compliant transactions or missing restricted parties.
This doesn't mean every entity screens identically. They should all work from the same current information and apply rules matching their specific obligations.
Who Owns Sanctions Screening?
Ownership depends on where the risk surfaces, which can be part of the problem. Underwriting screens at policy issuance, claims screens at payout, finance screens reinsurance settlements, and premium financing might sit with a third-party administrator with its own process. Without coordination, gaps emerge.
Compliance should own the sanctions framework, maintain centralized intelligence, and set screening standards. However, compliance can't approve every transaction. Business units execute screening using validated tools and workflows. Escalations and hits return to a central sanctions team for investigation and decision.
Key performance indicators and risk indicators feed back into your risk assessment. If claims generate more hits than underwriting, it indicates where designated parties are entering your book. If clearance times exceed targets, you have a resourcing or tooling issue that could lead to regulatory exposure.
Handling Reinsurance and Third-Party Settlements
Screen reinsurance and third-party settlements as you do direct payments. Reinsurance involves additional parties: the reinsurer, brokers, and ultimate beneficiaries. Third-party payments for premium financing, claims administration, or vendor services add more names. Each is a potential entry point for a restricted party.
Your screening process must capture the full payment chain, not just the immediate counterparty. If settling a reinsurance claim, screen the reinsurer, broker, and any downstream entities. If a third-party administrator handles claims, their screening standards must match yours, and you need audit rights to verify compliance.
Contract language is crucial. Reinsurance agreements and third-party service contracts should include sanctions warranties and give you the right to halt payments if a restricted party appears. Without this language, you're relying on goodwill instead of a legal obligation.
Next Steps
For more information, consult the FCA's May 2026 findings on sanctions compliance on their website, which include specific control weaknesses observed across firms. The EU's sanctions packages are published in the Official Journal with full legal text. OFAC maintains current designations and guidance on the US Treasury website. If your organization operates across multiple jurisdictions, consider joining a peer forum where compliance officers share approaches to divergent regimes. The questions won't get easier, but you're not solving them alone.



