The conventional wisdom
Most compliance teams see sanctions screening as a basic gatekeeping task. You screen customers at onboarding, check counterparties before transactions, and run periodic name checks against the OFAC Specially Designated Nationals list and other watchlists. If nothing flags, you're in the clear. The securities? Those are for the portfolio manager to worry about, not the compliance team.
This separation made sense when sanctions mainly targeted individuals and shell companies moving money through banks. Screen the name, block the payment, file the report. Simple and contained.
Why this approach is outdated
This model fails when your institution deals with capital markets. The risk isn't just in who you're doing business with; it's in the instruments your clients hold, the funds they invest in, and the structured products in custody accounts.
Consider OFAC's 50 Percent Rule. An entity becomes blocked if designated persons own 50% or more, even if that entity isn't on a sanctions list. You're not just matching names anymore. You're analyzing ownership through parent companies, subsidiaries, and beneficial ownership chains across jurisdictions.
Take an exchange-traded fund (ETF) as an example. The ETF itself isn't sanctioned, nor is the fund manager. But deeper down, one of the ETF's holdings includes an issuer where a blocked person holds more than 50% ownership. Your name screening passed. Your transaction monitoring passed. Yet, you still have sanctioned exposure in the portfolio.
Since 2024, OFAC has settled actions involving securities transactions at EFG International, Interactive Brokers, and TradeStation Securities. The message is clear: securities activity is a core compliance concern. Regulators expect you to look through the instruments, not just screen around them.
The evidence
Traditional name screening falls short in three key areas.
First, layered fund structures hide exposure. An ETF can hold another ETF, which holds another ETF, with the sanctioned security at the third level. Your screening tool checks the top-level instrument against the SDN list and finds nothing, because the issue isn't the fund wrapper. It's what's inside.
Second, jurisdictional differences create inconsistent risk profiles for the same instrument. A security might trigger EU sanctions but not OFAC restrictions. It might be permissible to hold but prohibited to trade. A binary screening result doesn't capture that nuance, and your risk-based approach requires exposure intelligence, not just a yes/no flag.
Third, structured products and options introduce derivative exposure that name screening can't detect. You might hold a product issued by a clean institution that references a sanctioned underlying or includes settlement terms tied to restricted instruments. The counterparty passes screening. The exposure doesn't.
OFAC distinguishes between ownership and control under the 50 Percent Rule. Control alone doesn't automatically trigger blocking requirements, though OFAC urges caution where a designated person holds significant minority ownership or exercises influence through other means. This distinction matters when evaluating whether an issuer's ownership structure creates reportable exposure, illustrating the limitation of list-based screening. You need ownership data and aggregation logic, not just a name match.
What to do instead
Treat securities screening as a distinct control, separate from customer and payment screening. They serve different functions and require different data.
Your customer screening identifies whether you're doing business with a blocked person. Your securities screening identifies whether the instruments in scope contain exposure to blocked persons or restricted issuers. One is about the relationship. The other is about the asset.
Build look-through capability for funds and ETFs. You need to see holdings at least three levels deep, with daily updates reflecting portfolio changes, corporate actions, and ownership restructuring. If your current vendor provides only top-level instrument screening, you're missing the exposure inside the wrapper.
Integrate beneficial ownership data into your securities screening process. The 50 Percent Rule requires aggregation across direct and indirect ownership. Connect issuer records to parent entities, track ownership chains, and calculate aggregate blocked-person interests even when no single blocklist entry exceeds 50% individually.
Establish clear accountability for portfolio-level sanctions risk. In many firms, compliance screens the customer and payments teams screen the transactions, but no one owns the instruments. Assign that responsibility explicitly. Define what gets screened (all holdings, new purchases only, certain asset classes), how often, and what triggers escalation to your MLRO.
Document your risk-based approach to exposure findings. Not every flagged instrument requires immediate liquidation. Some jurisdictions permit holding but not trading. Some sanctions regimes include wind-down provisions. Some exposures fall below your risk tolerance threshold. Record the analysis, the decision, and the control you applied.
When the conventional wisdom is right
Name screening still matters. You need to screen customers, counterparties, and payment beneficiaries against sanctions lists. That control isn't going away, and it catches most straightforward sanctions risks before they enter your institution.
For firms that don't custody securities, manage investment portfolios, or facilitate securities transactions, traditional name screening may be sufficient. If your business model is limited to deposit accounts and payment processing, instrument-level screening adds complexity without proportional risk reduction.
Even in capital markets, not every instrument requires the same scrutiny. A U.S. Treasury bond doesn't need the same look-through analysis as an emerging-market ETF with exposure to state-owned enterprises. Apply resources where the risk justifies the effort.
But if your institution holds, trades, or provides custody for securities, treating sanctions compliance as purely a name-screening exercise leaves exposure undetected until a regulator finds it first. The fines at EFG International, Interactive Brokers, and TradeStation Securities all involved securities activity, not payment screening failures. That's where the enforcement focus has shifted, and your controls need to follow.



