Purpose of the Template
As a sanctions analyst, you're tasked with reviewing alerts from your screening system. When a match is flagged, you must decide whether to escalate, clear, or investigate further. This decision becomes more complex when digital assets intersect with shadow banking networks.
This template is your guide for escalation when potential sanctions exposure involves cryptocurrency exchanges, payment intermediaries, or entities connected to sanctioned actors through ownership or transaction patterns, rather than direct name matches. It addresses the scenario highlighted by OFAC on August 7, when it sanctioned Iranian digital asset exchanges linked to the Islamic Revolutionary Guard Corps (IRGC) and exchange houses using corporate structures across multiple jurisdictions.
The template fills a specific gap: your name screening tool flagged something, but you need a structured process to evaluate whether a crypto exchange, payment processor, or trading company represents indirect exposure under OFAC's 50 Percent Rule or through network relationships.
Prerequisites
Before using this template, ensure you have:
Access to:
- Your institution's sanctions screening platform
- Beneficial ownership databases (corporate registry access, commercial KYB tools, or internal records)
- Entity-linkage intelligence (corporate family trees, shared directors, common addresses)
- Adverse media monitoring (news aggregators, sanctions-focused feeds, or manual search protocols)
- Digital asset intelligence sources (blockchain analytics platforms if you handle crypto transactions; otherwise, third-party reports on wallet addresses and exchange relationships)
Knowledge of:
- OFAC's 50 Percent Rule: entities owned 50% or more, directly or indirectly, by blocked persons are themselves blocked, even if they don't appear on the Specially Designated Nationals (SDN) List
- Your institution's risk appetite for jurisdictions with active sanctions-evasion networks (Iran, North Korea, Syria, Russia)
- Your escalation thresholds and who receives Level 1, Level 2, and MLRO-level escalations
Documentation ready:
- Customer due diligence file for the flagged relationship
- Transaction history (if the alert stems from payment activity rather than onboarding)
- Existing risk rating for the customer or counterparty
The Escalation Template
Copy this into your case management system or adapt it for your workflow tool:
CASE ID: [Auto-generated or manual]
DATE OPENED: [YYYY-MM-DD]
ANALYST: [Your name]
ALERT SOURCE: [Screening system name or manual referral]
Section 1: Initial Match Details
Flagged Entity Name: [Exact name from alert]
Match Type: [Direct SDN match / Alias match / Possible variant / Entity-linkage flag / Adverse media trigger]
Screening List(s): [OFAC SDN / EU Consolidated List / UN / OFSI / Other]
Match Confidence: [High / Medium / Low, based on name similarity, date of birth, address, or other identifiers]
Customer/Counterparty Name: [Legal name of your customer or the entity in the transaction]
Jurisdiction(s): [Where the entity is registered, where it operates, where the transaction originated]
Business Type: [Cryptocurrency exchange / Payment processor / Trading company / Exchange house / Shipping / Other]
Section 2: Ownership and Control Analysis
Beneficial Owner(s) Identified: [Yes / Partial / No]
If yes, list names and ownership percentages:
- [Name, % ownership, jurisdiction]
- [Name, % ownership, jurisdiction]
50 Percent Rule Exposure: [Evaluate whether any beneficial owner is a blocked person or entity]
- Does any single blocked person or entity own ≥50% directly? [Yes / No / Unable to determine]
- Does any combination of blocked persons collectively own ≥50%? [Yes / No / Unable to determine]
- Is the entity owned ≥50% by another entity that is itself blocked or majority-owned by blocked persons? [Yes / No / Unable to determine]
Corporate Linkages Found:
- Shared directors: [Names, other entities they control]
- Shared addresses: [Address, other entities at same location]
- Related entities: [Parent companies, subsidiaries, sister companies]
Red Flags in Ownership Structure:
- Opaque ownership (nominee shareholders, bearer shares, offshore trusts)
- Frequent ownership changes
- Ownership by entities in high-risk jurisdictions
- Ownership by entities previously flagged in adverse media
Section 3: Digital Asset and Transaction Context
Does this entity handle digital assets? [Yes / No / Unknown]
If yes:
- Type of digital asset activity: [Exchange / Custody / Payment processing / Mining / Other]
- Known blockchain addresses or wallet identifiers: [List if available, or note "not available"]
- Exposure to previously designated exchanges: [Any known transaction history or relationship with OFAC-designated crypto entities?]
Transaction Pattern Analysis:
- Transaction volume: [Approximate monthly/annual volume if known]
- Counterparty jurisdictions: [List countries involved in payment flows]
- Use of intermediaries: [Does the entity route payments through third-party processors, correspondent banks, or nested accounts?]
Specific Red Flags:
- Transactions involving Iran, North Korea, Syria, Russia (sanctioned programs), or other OFAC-sanctioned jurisdictions
- Use of intermediary accounts in UAE, Hong Kong, Singapore, or China (jurisdictions mentioned in OFAC's August 7 action as part of Iranian shadow banking networks)
- Payments related to oil, shipping, or commodities (sectors commonly exploited for sanctions evasion)
- Involvement of exchange houses or money service businesses with limited regulatory oversight
Section 4: Adverse Media and Open-Source Intelligence
Adverse Media Search Conducted: [Yes / No]
Search Terms Used: [Entity name, beneficial owner names, related company names, blockchain addresses]
Date Range Searched: [YYYY-MM-DD to YYYY-MM-DD]
Findings:
- Entity named in sanctions-related reporting
- Entity linked to sanctioned actors in investigative journalism
- Entity associated with IRGC, Qods Force, or other designated organizations
- Entity involved in sanctions-evasion schemes (front companies, shell companies, false documentation)
- No adverse media found
Sources Consulted: [List: Google News, sanctions-focused newsletters, blockchain intelligence reports, regulatory announcements, other]
Section 5: Risk Assessment and Escalation Decision
Overall Risk Rating: [High / Medium / Low]
Rationale: [Summarize your findings in 2-4 sentences. Example: "The entity is a UAE-based exchange house with opaque ownership. Beneficial ownership records show a 60% stake held by an entity registered in a jurisdiction known for Iranian front companies. Adverse media links the entity to facilitating Iranian trade payments. Transaction history shows payments routed through Hong Kong intermediaries."]
Escalation Decision:
- Clear Alert, False positive, no sanctions risk identified. Document reason and close.
- Request Additional Information, Insufficient data to assess. Specify what's needed (updated KYC, source of funds, transaction details, beneficial ownership documentation).
- Escalate to Level 2 Analyst, Possible indirect exposure; requires deeper investigation.
- Escalate to MLRO, High likelihood of sanctions violation; recommend blocking transaction or freezing account pending legal review.
- File Suspicious Activity Report, If sanctions violation is confirmed or if activity meets SAR thresholds under your jurisdiction's rules.
Action Taken: [Describe next steps: alert cleared, customer contacted for documentation, transaction blocked, account frozen, OFAC contacted, SAR filed, etc.]
Supporting Documentation Attached:
- Screening match report
- Beneficial ownership records
- Adverse media search results
- Transaction history
- Correspondence with customer
- Other: [Specify]
Customizing the Template
Adapt Section 2 for your data sources. If you don't have access to beneficial ownership databases, replace the checklist with "Request beneficial ownership documentation from customer" and set a deadline. If you use a commercial KYB tool, add fields for the tool's entity ID or risk score.
Modify Section 3 based on your institution's exposure. If you don't handle cryptocurrency, remove the blockchain address fields and focus on payment intermediaries and correspondent banking relationships. If you operate a crypto exchange, add fields for wallet clustering analysis and on-chain transaction tracing.
Adjust escalation thresholds in Section 5. Your institution's risk appetite determines when you escalate. A conservative approach might escalate any Iranian nexus to the MLRO. A more risk-tolerant approach might allow Level 2 analysts to clear alerts involving low-value transactions with weak entity linkages. Document your thresholds in your sanctions compliance policy and reference them in the template.
Integrate this template into your case management system. Most sanctions screening platforms allow custom workflows. Build this template as a structured form so analysts complete each section before closing an alert. If your system doesn't support custom forms, use this as a checklist in your investigation notes.
Update the red-flag lists regularly. The jurisdictions and sectors flagged in Section 3 reflect OFAC's August 7 action. As new designations emerge, add relevant typologies. For example, if OFAC targets a new evasion method, add it to your red-flag checklist.
Validation Steps
After customizing the template, test it:
Run a historical case. Pull a closed alert from the past six months that involved entity-linkage analysis or beneficial ownership questions. Complete the template as if you were investigating it fresh. Compare your conclusion to the original decision. Does the template surface the same risk factors? Does it highlight anything the original analyst missed?
Conduct a peer review. Have another analyst use the template on the same historical case without seeing your work. Compare results. If you reach different conclusions, the template needs clearer guidance in Section 5 (risk assessment criteria).
Check for completeness. Every section should have an answer or a documented reason why it's not applicable. If analysts frequently skip sections, either remove them or add guidance on when they're required.
Measure time-to-decision. Track how long it takes to complete the template for 10 alerts. If it's adding more than 15 minutes per alert, simplify Section 2 or Section 4. The goal is structure, not bureaucracy.
Update quarterly. Review OFAC's enforcement actions, typology reports from FATF, and your institution's internal audit findings. Add new red flags, remove outdated ones, and adjust escalation thresholds based on what you're seeing in real alerts.
This template won't catch every sanctions risk, but it gives you a repeatable process for scenarios that name screening alone won't solve. When digital assets and shadow banking networks intersect, you need more than a match score. You need a framework that forces you to ask the right questions.



