Skip to main content
Should You Screen Subcontractors Like Customers?Sanctions Lists & Screening
4 min readFor AML Compliance Officers

Should You Screen Subcontractors Like Customers?

The question divides compliance teams in organizations with complex supply chains: Should your third-party vendors receive the same scrutiny as direct customers? Investigative journalist Zack Kopplin from the Organized Crime and Corruption Reporting Project revealed a Pentagon fuel subcontractor linked to individuals connected to U.S. sanctions targets in Iraq and Lebanon. This case shows what happens when subcontractors aren't thoroughly vetted.

For AML compliance officers, this isn't just academic. It's a resource allocation problem with regulatory consequences. Your customer due diligence framework is mature, tested, and likely costly. Extending that same rigor to every tier of your supply chain seems wise until you consider the number of vendors.

The Case for Full-Spectrum Screening

The regulatory logic is clear: sanctions violations don't care about your org chart. Paying a subcontractor who employs a designated person means you've just moved money to a sanctions target. OFAC doesn't distinguish between direct payments and those buried in a procurement chain.

Proponents of comprehensive vendor screening highlight the opacity problem. Shell companies and beneficial ownership structures exist to hide connections that would fail a basic name screening check. If you're only screening the prime contractor, you're trusting them to screen their subs, and so on. Kopplin's investigation showed how this breaks down.

The beneficial ownership transparency argument strengthens this position. Without knowing who controls your nth-tier supplier, you can't assess sanctions risk. You're essentially running name screening against a corporate veil designed to defeat it. The golden passport issue compounds this: high-risk individuals can acquire citizenship in low-scrutiny jurisdictions, then use those credentials to establish seemingly clean corporate structures.

From this perspective, anything less than customer-grade due diligence on vendors is compliance theater. You're checking boxes without managing risk.

The Case for Risk-Based Pragmatism

The opposing view doesn't dispute the risk, but the feasibility.

Consider the math. A mid-sized financial institution might have 50,000 active customers and 2,000 vendors. That sounds manageable until you realize those vendors have their own suppliers. A payment processor working with e-commerce platforms isn't contracting with 2,000 companies. It's contracting with 2,000 companies that collectively work with hundreds of thousands of merchants. Do you screen them all?

Pragmatists argue that supply chain due diligence requires different tools than customer due diligence. You can't demand passport copies and proof of address from every employee of every subcontractor. You can't conduct periodic reviews of entities you don't directly contract with. The legal authority isn't there, and the operational capacity doesn't scale.

Instead, they advocate for targeted controls: contractual flow-down requirements that obligate prime contractors to screen their subs, certification programs, industry-specific standards, and focused screening of high-risk categories. If you're procuring fuel in Iraq and Lebanon, that's a different risk profile than buying office supplies in Luxembourg. Allocate resources accordingly.

This camp also points to the false positive problem. Expanding name screening to every entity in your supply chain multiplies your alert volume without necessarily improving detection. You end up drowning analysts in low-quality matches while actual sanctions evasion networks use the same beneficial ownership opacity they always have.

Where Practitioners Actually Land

Most compliance teams operate somewhere between these poles, and the position shifts based on sector and regulator.

Defense contractors and government suppliers face explicit requirements. The Federal Acquisition Regulation includes screening obligations that flow down through procurement tiers. You don't get to opt out based on resource constraints.

Financial institutions typically implement tiered approaches. Direct vendors receive enhanced due diligence. High-risk categories (correspondent banking, payment processing, cross-border services) trigger deeper screening. Everything else gets basic name checks and contractual attestations.

The trend is clearly toward more scrutiny, not less. The Corporate Transparency Act will eventually make U.S. entity ownership more visible, reducing (but not eliminating) the shell company problem. The EU's Anti-Money Laundering Authority is pushing similar transparency mandates.

But transparency only helps if you're looking. Kopplin's reporting didn't uncover a sophisticated sanctions evasion scheme. It uncovered basic due diligence failures in a government supply chain that theoretically had robust vetting requirements.

Our Take

The answer isn't binary, but the starting assumption should be clear: if a payment to a vendor could violate sanctions, you need controls that would catch it.

That doesn't mean treating every supplier like a high-risk customer. It means building a vendor risk framework that accounts for sanctions exposure at each tier. Start with three questions:

What's the payment path? If funds flow directly to entities in high-risk jurisdictions or sanctioned sectors, your screening needs to match that risk. The Pentagon fuel subcontractor case illustrates this perfectly: procurement in Iraq and Lebanon demands scrutiny that office supply contracts don't.

What's the beneficial ownership visibility? When you can't identify who controls a vendor, you can't screen them. Either obtain that information through contractual requirements or treat the opacity itself as a risk factor that triggers enhanced measures.

What's your contractual leverage? Flow-down clauses that require prime contractors to screen and certify their subs shift some burden, but only if you verify compliance. Attestations without audits are just paperwork.

The resource constraint argument is real, but it's not a compliance defense. If your supply chain is too complex to screen effectively, you have three options: simplify it, build better screening technology, or accept that you're operating with sanctions risk you can't measure. Only the first two are defensible.

Golden passports and anonymous shell companies will continue to obscure beneficial ownership until global transparency standards catch up. Until then, your vendor due diligence framework needs to assume that some percentage of your supply chain is deliberately opaque. The question is whether you're screening hard enough to find the Pentagon fuel contractors before a journalist does.

You Might Also Like