Skip to main content
Sanctions Compliance Isn't About Waiting for PermissionSanctions Lists & Screening
4 min readFor Payments Compliance Teams

Sanctions Compliance Isn't About Waiting for Permission

The Conventional Approach

Most compliance teams believe that when OFAC removes a country from the State Sponsors of Terrorism (SST) list, the best course is to wait. You wait for internal counsel to review, for banking partners to confirm their position, and for industry guidance. You wait until you're sure there's no residual sanctions risk before enabling transactions.

This approach seems prudent. Syria was on the SST list for decades, triggering prohibitions under Section 40 of the Arms Export Control Act, restrictions on foreign assistance, and secondary sanctions that created significant compliance liability. When the US removed Syria from that list, a cautious response seemed sensible: let someone else go first.

However, Visa and Mastercard didn't wait. They completed their first international card transactions in Syria shortly after the designation change.

Why Waiting Isn't Enough

The wait-and-see approach mixes two distinct compliance questions. The first is legal: what does the current sanctions framework allow? The second is strategic: what level of residual risk will you accept in a newly accessible market?

Treating these as a single question leads to inaction. You're essentially saying, "We won't operate unless the compliance path is completely clear and someone else has tested it first."

But here's the issue: OFAC doesn't issue all-clear signals. The removal of Syria from the SST list doesn't mean Syria is sanctions-free. Executive Order 13894 remains in place. The Syrian government and specific Syrian entities are still on the Specially Designated Nationals (SDN) List. Section 311 of the USA PATRIOT Act still designates the Commercial Bank of Syria as a primary money laundering concern.

If you're waiting for a green light, you'll wait forever. What changed is that one specific prohibition lifted. Your compliance obligation is to understand exactly which prohibition that was, what remains, and whether you can build controls around the residual exposure.

Understanding the Changes

Consider what the SST designation actually did. It blocked financial transactions with the Syrian government, required a presumption of denial for export licenses, and created secondary sanctions exposure for non-US entities dealing with Syria in specific contexts.

The removal means those specific restrictions no longer apply. It doesn't affect:

  • SDN List sanctions: You still can't process transactions involving designated Syrian individuals or entities. Your name screening obligations haven't changed.
  • Sectoral sanctions: If EO 13894 prohibits dealings with certain Syrian sectors, those prohibitions persist.
  • Section 311 measures: Syrian financial institutions designated under the Bank Secrecy Act remain high-risk. Your enhanced due diligence requirements stay in place.

The compliance question isn't "Is Syria safe now?" It's "Can we build a Customer Due Diligence and transaction monitoring framework that catches prohibited transactions while enabling legitimate ones?"

Visa and Mastercard answered yes. They already had the infrastructure: real-time name screening, merchant category code controls, and transaction pattern analysis. The SST removal meant they could turn on processing for Syrian cardholders without violating the specific prohibition that designation created.

Steps to Take

When a sanctions designation changes, map the regulatory delta immediately. Don't wait for industry consensus. Ask:

  1. Which specific prohibition lifted? In this case, the SST designation. Not "Syria sanctions generally" but the particular legal authority that designation invoked.

  2. What sanctions remain in force? Review the current SDN List entries for Syrian nexus. Check active Executive Orders. Verify sectoral prohibitions. Your name screening rules need to catch these.

  3. What's your existing control coverage? If you already screen transactions against OFAC lists in real time and block matches automatically, you have the foundation. The question becomes: can you tune your monitoring rules to detect evasion patterns specific to this market?

  4. What's your risk appetite for this jurisdiction? This is the strategic question. Syria's corruption perception ranking, money laundering risk, and terrorist financing exposure haven't changed overnight. If your institution's risk appetite is conservative, you might still choose to avoid Syrian exposure. But that's a business decision, not a compliance mandate.

  5. What enhanced due diligence will you apply? For Syrian counterparties, consider: beneficial ownership verification through independent sources, adverse media screening with Syria-specific keywords, transaction pattern analysis for structuring or sanctions evasion typologies, and periodic review intervals shorter than your standard schedule.

Build your compliance memo around these questions. Document your analysis. If you decide to enable transactions, explain your control framework. If you decide to maintain restrictions, explain that it's a risk appetite decision, not a regulatory requirement.

When Waiting Makes Sense

The wait-and-see approach has merit in three scenarios:

First, when you lack the control infrastructure. If you can't screen transactions in real time or rely on batch processing that creates settlement risk, waiting makes sense. You need to build the controls before you enable the exposure.

Second, when the regulatory change is ambiguous. The Syria SST removal was clear: a specific list designation was revoked. But sometimes OFAC issues general licenses with vague scope or provides guidance that leaves interpretation questions open. In those cases, waiting for FAQ updates or industry coordination reduces your interpretive risk.

Third, when you're a small institution without dedicated sanctions expertise. If you don't have the resources to map the regulatory delta yourself, following your larger competitors' lead is rational. Just understand that you're accepting a competitive timing disadvantage in exchange for reduced analytical burden.

For everyone else, the conventional wisdom isn't prudence. It's risk transfer dressed up as caution. Your job is to understand what the law requires and build controls that meet that standard, not to wait until compliance feels comfortable.

You Might Also Like