Compliance PracticeEurope

UK Financial Firms Improve Sanctions Controls, but Screening and Alert-Management Gaps Remain

UK financial firms have strengthened their sanctions controls since 2022, but weaknesses in customer due diligence, screening, alert handling and frozen-asset management continue to cause suspected breaches, according to a new review by the Financial Conduct Authority.

The FCA has assessed the sanctions systems and controls of more than 150 firms across different financial services sectors since February 2022. It found repeated examples of firms identifying potential breaches before they occurred, supported by stronger governance, more frequent screening and better use of internal and external assurance.

However, the regulator said the most common causes of reported breaches remained:

  • Weak customer due diligence;
  • Deficiencies in customer, counterparty and payment screening;
  • Poor alert management;
  • Failures to freeze assets promptly or keep them frozen; and
  • Non-compliance with the terms of sanctions licences.

Firms also appeared better prepared for financial sanctions than for trade sanctions, where restrictions may depend on the goods, services, vessels, end users and jurisdictions involved.

Where Firms Have Improved

The FCA found that automated and repeat screening have become common across the financial sector.

Among firms reporting relevant data:

  • 70% used automated sanctions screening;
  • 81% repeatedly screened existing customers;
  • 76% conducted name screening daily; and
  • 73% screened transactions or payments at least daily.

Firms with stronger controls had clear screening policies, defined escalation procedures and documented responsibility across compliance and operational teams.

Better-performing firms also used sanctions risk assessments to guide customer reviews, supplemented screening with corporate ownership analysis and applied role-specific training to employees working in higher-risk areas.

These developments suggest that sanctions compliance is becoming more embedded within firms’ financial crime frameworks rather than being treated as a periodic list-checking exercise.

Due Diligence Gaps Remain

The FCA found that some firms still struggled to identify entities owned or controlled by designated persons.

The risk was particularly difficult to assess where customers had:

  • Multilayered ownership structures;
  • Nominee or intermediary arrangements;
  • Indirect links to designated persons;
  • Overseas branches or group entities; or
  • Complex investment and distribution chains.

Some firms relied heavily on customer self-declarations or outdated sanctions questionnaires without independently confirming the information.

Initial screening may establish that a customer is not directly named on a sanctions list. It does not necessarily identify whether a designated person owns, controls or benefits from the customer through other entities.

Ongoing due diligence is therefore important when ownership changes, new counterparties appear or external information reveals previously unknown sanctions exposure.

Screening Systems Still Miss Relevant Matches

The FCA identified weaknesses in the design and operation of screening systems.

These included:

  • Outdated or incomplete sanctions lists;
  • Poor data quality;
  • Inadequate matching of spelling and name variations;
  • Weak handling of names written in non-Latin scripts;
  • Screening rules that excluded relevant information;
  • Delays in updating systems after new designations; and
  • Limited understanding of third-party screening tools.

In one case described by the FCA, a firm’s system failed to identify a designated person because its phonetic and spelling-variation rules were inadequate.

In another, a wholesale bank failed to identify payments referring to vessels connected with a designated person because its screening rules required specific prefixes or formats.

These examples show that purchasing a screening system does not transfer responsibility to the technology provider. Firms must understand what the system screens, how it matches information and where its limitations lie.

Why an Alert Is Not the Same as an Effective Control

A screening alert only indicates that the system has identified a possible match.

The control becomes effective only when the alert is:

  1. Generated using complete and current data;
  2. Prioritised according to risk;
  3. Reviewed by a properly trained analyst;
  4. Escalated when the match cannot be resolved;
  5. Acted upon before funds or assets are released; and
  6. Supported by documented reasoning and quality assurance.

The FCA found that alert handling was a common cause of suspected sanctions breaches.

Only around 44% of firms reported resolving name-screening alerts within one working day on average. A similar proportion—47%—resolved payment-screening alerts within that timeframe.

More than a quarter of firms took between three and five days to resolve name alerts, while around one-fifth took the same period for payment alerts.

Long review times do not automatically indicate a breach, particularly where a case is complex. The greater risk arises when transactions continue or assets remain accessible while a potentially valid match is being investigated.

The FCA identified cases where firms generated appropriate alerts but still released transactions because of delays, weak handovers or unclear escalation processes.

A system that produces an alert but does not lead to timely and accurate action cannot be considered an effective sanctions control.

Frozen Assets and Licences Require Continuing Management

Sanctions compliance does not end when an account is initially frozen.

Firms must ensure that restrictions remain in place and that funds are not released accidentally through:

  • Returned or reversed payments;
  • Interest or fee processing;
  • Manual account adjustments;
  • System changes;
  • Expired internal controls; or
  • Errors during alert review.

The FCA found cases where firms did not apply restrictions while potential matches were being investigated or lacked clear deadlines for freezing accounts and blocking transactions.

Specific and general licences also require active management. A licence may permit only certain payments, parties, amounts or purposes and may impose reporting or recordkeeping conditions.

Treating a licence as a general exemption can expose a firm to transactions outside its permitted scope.

Trade Sanctions Need Broader Controls

Name and payment screening may be sufficient to identify some financial sanctions risks, but they are less effective for trade and sectoral restrictions.

A prohibited transaction may involve a non-designated customer trading restricted goods through an intermediary. The payment message may contain no obvious sanctions reference.

The FCA noted that stronger firms supplemented screening with:

  • Vessel tracking;
  • Corporate ownership analysis;
  • Review of trade and shipping documents;
  • Internal watchlists;
  • Transaction monitoring; and
  • Intelligence-led investigations.

This is particularly relevant where firms finance international trade, provide maritime insurance or serve customers involved in higher-risk goods and jurisdictions.

The Compliance Significance

The FCA’s review does not suggest that screening technology is becoming less important. It shows that screening must operate as one part of a wider control framework.

An effective sanctions programme needs current customer information, reliable data, properly calibrated systems, trained investigators and clear procedures for freezing assets and managing licences.

Firms should pay particular attention to the period between the generation of an alert and the final decision.

That is often where an apparently functioning control fails: the alert exists, but it is reviewed too slowly, closed on incomplete information or not translated into an effective restriction.

The key measure is therefore not how many alerts a firm generates.

It is whether the firm can identify genuine sanctions exposure and act before a prohibited transaction or release of assets occurs.

Main Source

Financial Conduct Authority — Sanctions Systems and Controls in Our Firms: Our Findings

https://www.fca.org.uk/publications/good-and-poor-practice/sanctions-systems-and-controls-our-firms-our-findings

Adminrichie

AML Observatory Webmaster, responsible for the website's operations.

Related Articles

Leave a Reply

Back to top button