Sanctions Screening
Sanctions screening in crypto covers customers, counterparties and—where relevant—blockchain addresses and transactional exposure. It must use the sanctions law applicable to the f
Reading progress — saved on this device
Learning objectives
- Distinguish list screening from blockchain exposure analysis.
- Understand ownership/control and jurisdictional scope issues.
- Design escalation for exact matches, near matches and address-risk alerts.
What the rule or control is
Traditional sanctions screening compares names and identifiers against official lists. Crypto adds published wallet addresses and blockchain exposure analysis, but addresses are not a complete list of sanctioned property and address reuse/control can change.
Jurisdiction matters. UK, EU, US and UN regimes differ in scope, ownership/control tests, licensing and reporting obligations. A multinational firm may need to apply several regimes. Screening tools should therefore preserve which list/version produced an alert.
Address analytics should be treated cautiously. Direct interaction with a designated address is different from remote indirect exposure. Analysts should validate attribution, transaction path, timing and legal scope before deciding whether assets must be frozen or activity rejected.
Further analysis
Screening programmes also require change management because designations, aliases and ownership structures evolve. Re-screening frequency should reflect risk and legal requirements, with urgent handling for list updates. False positives need documented resolution; false negatives require quality testing using representative names, scripts and transliterations. In crypto, firms should also assess whether their analytics provider covers the relevant chains and whether a designation has been mapped to associated addresses with an evidential basis. Where sanctions ownership or control is legally complex, firms should escalate to specialist legal analysis rather than forcing a binary automated decision.
Control governance
Escalation procedures should define what staff do when a potential match appears: pause or restrict activity where legally required, preserve evidence, seek legal or sanctions-specialist input, make required reports and document any licence or exemption relied on. Because sanctions breaches can carry serious consequences, firms should test not only whether screening fires but whether the operational response is timely and legally accurate.
Decision framework
| Question | Why it matters |
|---|---|
| Jurisdiction | Rules differ by customer, entity, activity, location and regulator. |
| Legal classification | The same commercial label can cover legally different products or activities. |
| Evidence | Keep primary-source rules, transaction evidence and dated assumptions. |
| Change control | Re-check when legislation, guidance, product design or customer journey changes. |
Worked example and thought exercise
A customer's wallet received funds two years ago from an address later added to a sanctions list. The legal analysis depends on designation date, current ownership/control, transaction facts and applicable regime. A current vendor label alone does not answer whether the historical receipt was prohibited.
Thought exercise: Which fact in the example would most change the legal, tax or compliance conclusion if it were different?
Common mistakes and practical workflow
- Using one sanctions list for all jurisdictions.
- Assuming every indirect blockchain link requires automatic freezing.
- Failing to screen beneficial owners and controllers.
- Not documenting list versions and alert disposition.
Practical workflow
- Define the exact activity, asset, customer and jurisdictions.
- Find the current legislation/regulator or tax-authority source rather than relying on a secondary summary.
- Record the rule version/date and the facts used in the analysis.
- Document controls, evidence and any uncertainty or exceptions.
- Escalate to qualified legal, compliance or tax advice where the decision is material.
Primary sources to verify
- Official sanctions lists and regulator guidance applicable to the firm (e.g. OFSI, EU, OFAC).
- FATF virtual-asset guidance for risk context.
- Firm-specific legal advice for ownership/control and licensing questions.
These references identify the primary authority or official guidance used for the educational framework. Always verify the live version before relying on a rule.
Knowledge checkpoint
- What is the main legal/compliance distinction in Sanctions Screening?
- Which facts or jurisdictional assumptions could change the answer?
- Why should primary-source dates be recorded?
- What is one common mistake that could create compliance or tax risk?
FAQs
❓ Is this lesson legal or tax advice?
No. It is educational. Rules depend on jurisdiction, facts and date; professional advice may be appropriate.
❓ Why does the review date matter?
Crypto regulation and tax guidance change quickly, so legal claims should be checked against current primary sources.
❓ Should a vendor or dashboard be treated as an authority?
No. Vendor outputs are evidence inputs; legal and tax conclusions should be grounded in applicable law and regulator or tax-authority guidance.
❓ What should I do when jurisdictions conflict?
Identify every relevant jurisdiction and obtain qualified advice rather than assuming one country's rules control globally.
Summary
Sanctions screening in crypto covers customers, counterparties and—where relevant—blockchain addresses and transactional exposure. It must use the sanctions law applicable to the firm, not a generic internet blacklist. The disciplined approach is to separate labels from legal classification, record jurisdiction and date, preserve evidence, and verify current primary sources before acting.
Want this in a personalised order?
Take the crypto assessment and get a custom path of 10 modules matched to what you already know. Free, no card required.
Build my path →