Skip to main content
Sanctions Screening Isn't Enough AnymoreMoney Laundering Typologies
6 min readFor Sanctions Analysts

Sanctions Screening Isn't Enough Anymore

If you're still treating sanctions compliance as a simple list-matching exercise, you're missing the networks that regulators are now targeting. The UK's nationwide alert on the A7 network, issued on 31 August 2026, shows how sanctions evasion has evolved beyond direct counterparty screening. The network reportedly settled more than $86 billion in transactions within its first year by routing funds through third-country financial institutions and layered corporate structures.

Meanwhile, the UK government plans to double OFSI's maximum financial penalty from 50% to 100% of the breach value. Your screening controls need to catch up with how evasion actually works.

Why These Mistakes Keep Happening

Most sanctions compliance programs were built for a simpler threat model: screen your customer against sanctions lists, block the match, file the report. That worked when evasion meant a designated person opening an account under their own name.

Today's evasion networks operate through intermediaries in jurisdictions you don't directly transact with. They use nested correspondent banking relationships, shell companies registered in third countries, and cryptocurrency platforms that provide layering services. Your direct counterparty isn't on any list, but they're facilitating payments for entities that are.

The gap isn't usually a technology problem. It's a scoping problem. Teams screen what they can see in their immediate transaction data, but they don't have visibility into the full payment chain or the beneficial ownership structures behind their corporate customers.

Mistake 1: Screening Only Direct Counterparties

Why it happens: Your sanctions screening system flags matches in the immediate payment parties: originator, beneficiary, ordering institution. You don't have structured data about the underlying purpose of the payment or the parties two or three steps removed in the payment chain.

The consequence: You miss payments routed through third-country banks that serve as conduits for sanctioned entities. The A7 network's model depends on this blind spot. UK authorities specifically highlighted the network's use of third-country financial institutions to circumvent sanctions. Your screening engine never sees the ultimate beneficiary.

The fix: Implement enhanced due diligence triggers for payments involving jurisdictions frequently used as sanctions evasion hubs. When you onboard a corporate customer, map their correspondent banking relationships and identify whether they maintain accounts at institutions in Central Asia, West Africa, or other regions flagged in government alerts. For high-risk correspondent relationships, require additional documentation about the underlying customer base and transaction purposes.

You can't screen parties you can't see, but you can screen for the structural red flags that indicate hidden parties exist.

Mistake 2: Ignoring Beneficial Ownership in Sanctions Risk Assessments

Why it happens: Your Customer Risk Profile treats the corporate entity as the risk unit. You verify the company's registration and screen its legal name, but you don't systematically identify and screen beneficial owners, especially when the company is registered in a jurisdiction with weak transparency requirements.

The consequence: Sanctioned individuals control companies through layered ownership structures. Your screening system returns a clean result because the company name isn't on a list, but the person who ultimately controls it is. This is how professional money laundering networks operate. They don't put their names on anything you can screen directly.

The fix: Require Beneficial Owner Identification for all corporate customers, not just those above a certain transaction threshold. Screen every individual who owns or controls 25% or more of the entity. For customers in high-risk jurisdictions or sectors (such as import-export, precious metals, or cryptocurrency services), lower the threshold to 10%.

When beneficial ownership information isn't available through official registries, escalate to your MLRO before onboarding. The inability to identify beneficial owners is itself a red flag, not a documentation inconvenience.

Mistake 3: Treating Sanctions Screening as a One-Time Event

Why it happens: You screen customers at onboarding and assume your obligation is complete until the next Periodic Review. Sanctions lists update constantly, but your screening cadence doesn't.

The consequence: A customer who was clean at onboarding gets designated six months later. You continue processing their transactions until your annual review cycle catches the match, or until a regulator points it out during an examination. OFSI's proposed penalty increase means that delay now costs you up to 100% of every transaction you processed after designation.

The fix: Implement continuous sanctions screening that re-screens your entire customer base every time a sanctions list updates. Most modern screening platforms support this through automated batch processes. Configure your system to re-screen at least daily, or in real-time if your platform supports it.

For customers in high-risk categories (such as those with correspondent banking relationships in sanctions-prone jurisdictions, or those operating in sectors targeted by recent enforcement actions), increase the frequency to match the 15-minute update cycles that some sanctions data providers offer.

Mistake 4: Relying Solely on Name-Based Screening

Why it happens: Your screening system matches names and aliases from sanctions lists against your customer and transaction data. It's the standard approach, and it works for straightforward cases.

The consequence: You miss evasion through related entities, cryptocurrency addresses, vessel IMO numbers, and other non-name identifiers. The UK government's alert on the A7 network specifically mentioned the network's use of cryptocurrency infrastructure. If your screening system only looks at names, you won't catch a transaction routed through a designated crypto exchange.

The fix: Expand your screening to include entity relationships and non-name identifiers. When a sanctions list designates a company, manually review the designation notice for related entities, subsidiaries, and aliases. Add those to your internal watchlist even if they're not explicitly listed.

For cryptocurrency transactions, screen wallet addresses against blockchain intelligence platforms that track addresses associated with sanctioned entities. For maritime transactions, screen vessel IMO numbers against OFAC's SDN list, which includes vessel identifiers.

This requires manual curation, but it's the only way to catch the layered structures that evasion networks use.

Mistake 5: Ignoring Government Alerts and Typology Guidance

Why it happens: Your compliance program focuses on regulatory obligations: screen the lists, file the reports, maintain the records. Government alerts about specific networks or evasion methods feel like optional reading.

The consequence: You miss the context that explains why certain transaction patterns matter. The UK's A7 alert describes specific methods the network uses: third-country intermediaries, multi-jurisdictional structures, and misuse of correspondent banking. If you don't read the alert, you won't know to look for those patterns in your transaction data.

The fix: Assign someone on your sanctions team to monitor government alerts from OFSI, OFAC, and other relevant authorities. When an alert describes a specific evasion network or typology, translate it into screening rules or investigation triggers.

For the A7 network, that means flagging transactions involving third-country banks in Central Asia and West Africa, especially when those transactions involve parties with Russian or Iranian connections. Create a case management queue for these alerts and require your analysts to document how you've incorporated the guidance into your controls.

Prevention Checklist

  • Screen beneficial owners, not just corporate entity names
  • Re-screen your entire customer base at least daily against updated sanctions lists
  • Map correspondent banking relationships for corporate customers in high-risk sectors
  • Maintain an internal watchlist of entities related to designated parties, even if not explicitly listed
  • Review OFSI, OFAC, and NCA alerts monthly and translate them into investigation triggers
  • Screen non-name identifiers: cryptocurrency addresses, vessel IMO numbers, and entity registration numbers
  • Require enhanced due diligence for customers with business relationships in jurisdictions flagged in government alerts
  • Document your rationale when you cannot identify beneficial owners, and escalate to your MLRO before onboarding

Sanctions evasion networks don't bypass your controls by accident. They study how screening systems work and design their structures to exploit the gaps. Your job is to close those gaps before OFSI's new penalty structure makes them too expensive to ignore.

You Might Also Like