Financial Crime Intelligence Hub

Sanctions Screening Failure Modes.

Why sanctions screening can fail even when automated screening technology is in place — and why effective compliance extends beyond list matching.

Published by FCRisk · Last reviewed: 27 August 2026
Cross-case synthesis 05

Screening is a chain of dependent controls.

A sanctions-screening engine does not become effective simply because it is switched on. Effectiveness depends on who and what is screened, which lists and data are used, how matching is configured, how alerts are handled and what decisions follow.

FCRisk synthesis: sanctions compliance extends beyond list matching. Ownership/control, transaction context, asset restrictions, escalation, licensing and reporting can all matter after a screening event.

Screening-to-decision chain

Reference listsPopulationMatchingAlertInvestigationDecisionRestriction / report
Failure modes

Six places sanctions screening can fail.

01

Reference-list coverage

The control uses an incomplete, stale or incorrectly governed sanctions reference population.

02

Customer / payment coverage

Not all relevant customers, counterparties, payments or transaction data enter screening at the required point in the lifecycle.

03

Matching & calibration

Configuration, thresholds, fuzzy logic, spelling or transliteration handling do not identify risk reliably.

04

Alert management

Potential matches are delayed, incorrectly discounted or inadequately investigated.

05

Decision & escalation

Screening output does not lead to timely freezing, restriction, licensing, escalation or disclosure decisions.

06

Assurance & change

Testing, list-management governance, configuration control, MI and change assurance do not demonstrate ongoing effectiveness.

Evidence from enforcement and supervision

The failure is often wider than the matching algorithm.

Reference population · ConfigurationStarling · FCA

Automated screening operated against only part of the sanctions list.

Official finding. The FCA states that Starling discovered its automated screening system had for years been screening customers against only a fraction of the full list of persons subject to financial sanctions.

FCRisk synthesis. Reference-list completeness is a control-boundary dependency. A technically functioning matching engine can still operate on the wrong sanctions population.

Primary source — FCA ↗ · Final Notice ↗

Matching · Escalation · TrainingBank of Scotland · OFSI

Name variation exposed both screening and contingency weaknesses.

Official finding / lesson. OFSI's published lessons state that automated screening failed to detect a spelling variation of a designated individual's name and emphasise explicit contingency escalation and staff training.

FCRisk synthesis. Automation needs an operational fallback when matching confidence is imperfect or staff encounter a sanctions concern outside the automated path.

Primary source — OFSI ↗

Business model · Sanctions governanceBinance · OFAC

Sanctions failure can arise from enterprise choices, not only screening defects.

Official finding. OFAC stated that Binance matched and executed transactions involving U.S. users and users in sanctioned jurisdictions or blocked persons, while senior management knew of relevant sanctions risks and the platform's trade-matching implications.

FCRisk synthesis. Sanctions controls can fail at Risk & Scope and Governance & Assurance before a screening alert is ever generated.

Primary source — OFAC ↗

Restriction · DecisionWise · OFSI

Identifying sanctions risk must translate into effective restriction of activity.

Official finding. OFSI published a disclosure concerning a cash withdrawal from an account held by a company owned or controlled by a designated person, and later highlighted the importance of promptly identifying and acting on sanctions risks and ensuring screening and alert functions are available whenever firms are doing business.

FCRisk synthesis. Screening coverage has little value if designation status does not propagate into account controls and operational decisions.

Primary source — OFSI ↗

Current supervisory signal

FCA findings reinforce the full control chain.

The FCA's 2026 sanctions systems-and-controls review identifies themes across governance, risk assessments, due diligence, customer/payment screening, list management and data feeds, calibration/configuration/testing, alert management, evasion investigation, asset freezing and breach reporting.

FCRisk implication

Sanctions screening should be assured as an end-to-end control outcome: authoritative list → complete screening population → appropriate matching → alert decision → restriction/escalation/reporting → sustained testing and governance.

Primary source — FCA sanctions systems & controls review ↗

Official sources

Authoritative sanctions resources

Use the FCRisk Official Sources gateway to reach current UK, US, EU and UN sanctions resources directly from issuing authorities.

Explore Official Sources →

Framework

Control Failure Framework

Map sanctions weaknesses across boundary, data, configuration, operation, decision, assurance and remediation lenses.

Explore the framework →