Sanctions screening you can explain to an examiner.
Program design, alert disposition standards, ownership and control analysis, PEP and adverse media, and multi-regime screening across OFAC, U.K., E.U. and U.N. lists. We tune and test it inside the platforms you already run, with a written reason for every setting.
A Screening Program With a Reason for Every Setting
Every sanctions screening program eventually faces the same questions from an examiner, a bank partner or an auditor. Why these lists? Why this matching threshold? Which fields reach screening, and which do not? Who cleared this alert, on what evidence, and how fast? A program that cannot answer those questions in writing is hard to defend, even when it works.
OFAC can impose civil penalties on a strict liability basis, so a violation can occur without intent or knowledge. Its Enforcement Guidelines weigh the existence and quality of a compliance program when OFAC decides how to respond to an apparent violation. Its Framework for Compliance Commitments sets out five essential components: management commitment, risk assessment, internal controls, testing and auditing, and training.
Ethixera Advisory provides sanctions screening program design, interdiction system testing, and OFAC compliance frameworks for financial institutions and corporates. Our principal has led financial crimes programs across Top 10 U.S. banks, Big 4 advisory engagements, and cross-border organizations operating under DOJ, FinCEN, OFAC, and FATF expectations. Engagements are principal-led, with direct access to senior expertise.
Sanctions screening is one part of our financial crimes advisory practice, alongside AML program reviews and FCPA and third-party anti-corruption diligence.
Regulator-facing experience: direct engagement with FinCEN, state banking departments, FDIC and OCC exam teams and the DOJ, plus Big Four and national-firm validation work.
Where Clients Start
Sanctions work usually begins with a specific signal. Start where you are.
An alert backlog
Alerts are outrunning the team, false positives are burying the true matches, and some alerts are cleared without a documented reason. The queue needs standards, and the matching logic needs a risk-based look.
Screening tuning and testingA missed hit
A payment went through that should have been stopped, or a customer turned out to be owned by a blocked person. You need to know how it happened, what else it touched and what to fix, while your counsel weighs disclosure.
An exam or bank-partner review
Your examiner or sponsor bank has asked why you screen against these lists, at these thresholds, and who cleared each alert. The answers need to be written down and backed by evidence.
Sponsor bank readinessA new corridor or market
Payouts to new markets, new currencies or a new payout partner can bring U.K., E.U. and U.N. list exposure alongside OFAC. List coverage should be settled before the first transaction clears.
U.S.-Africa remittance corridor complianceA platform change
A new screening system, a migration or a core system change can quietly alter which fields and parties reach screening. Testing before and after the change shows nothing was lost on the way.
Aid work in a sanctioned market
A humanitarian program, or the payments that fund it, generally needs to fit within an exemption, a general license or a specific license. The records need to show each payment stayed within its terms.
What a Defensible Screening Program Needs
Each area can be scoped on its own or as part of a full program build or review. The work fits your risk: a community bank, a payments platform and a corporate with overseas distributors need different programs.
Program Design
A sanctions risk assessment that drives the program, policy and procedures your team can execute, clear ownership and escalation, board reporting and training. The design follows the five components in OFAC's Framework for Compliance Commitments, scaled for a bank, fintech, money services business or corporate.
Alert Queue & Disposition Standards
Written standards for how alerts are reviewed, which secondary identifiers can discount a match, when an alert escalates, who can release, block or reject, and what the file must show. We also set queue timeliness targets and quality review of cleared alerts, and map the blocked and rejected transaction reports OFAC requires.
Ownership & Control Analysis
A method for collecting ownership information, tracing direct and indirect ownership chains, and aggregating blocked persons' interests under OFAC's 50 percent rule. The U.K. and E.U. regimes apply their own ownership and control tests, so the analysis documents each regime's conclusion, not only OFAC's.
PEP & Adverse Media
Risk-based screening for politically exposed persons and adverse media at onboarding and on a set review cycle, with results that feed customer risk rating and enhanced due diligence. PEP and adverse media hits are not sanctions matches, so we keep their dispositions and escalation paths separate.
Multi-Regime Screening
List coverage set by where you operate, who your customers and counterparties are, which currencies you move and what your bank partners require. Coverage can span OFAC, the U.K. sanctions list, the E.U. consolidated financial sanctions list and the U.N. Security Council Consolidated List, plus country and region screening where a sanctions program covers a geography rather than a name.
Humanitarian License Advisory
For organizations delivering aid in sanctioned markets, and the banks and payment providers that move their funds. We map the activity against the humanitarian exemptions and general licenses that may apply, for your counsel to confirm. We build the controls and records that show each payment stays within them, and support your counsel when a specific license application is needed.
Tuned and Tested Inside the Platform You Already Run
Most screening problems are not solved by buying a new system. They sit in the data that reaches screening, the lists loaded into it, the way matching is configured and the standards the team uses to clear alerts. We work inside the screening platform you already run, whether it comes from a vendor or was built in-house, and we do not ask you to replace it.
Tuning starts with data. If a payment's beneficiary field never reaches screening, no threshold setting will catch the name in it. From there we test list currency, matching logic and thresholds, using test names and variations to show where the system detects and where it does not. Every change comes with a written rationale tied to your risk assessment, so an examiner sees risk-based tuning, not a cut in alert volume for its own sake.
Testing and tuning are different jobs. If Ethixera tuned your screening, the independent test of that work belongs to a different reviewer. For an independent test of the whole BSA/AML program, sanctions included, see our independent BSA/AML review and program testing.
Sponsor banks can commission the same testing on the screening a fintech partner runs under their program, as part of fintech partner oversight for sponsor banks.
Assess, Design, Tune, Test
Most engagements run in four steps. Some clients need all four; others start at the step where the pressure is. Timing depends on your size, your products and the platforms involved, and we confirm it at scoping.
- 01
Assess
We start from your products, customers, geographies, payment flows and bank-partner terms, and build or refresh the sanctions risk assessment that sets list coverage, screening points and review cycles.
- 02
Design
We write or revise the policy, procedures, alert disposition standards, ownership and control method, escalation paths and board reporting, so each decision in the program has an owner and a written rule.
- 03
Tune
Inside your platform, we trace data from source to screening, review list management and matching configuration, and recommend tuning changes with the rationale and test evidence behind each one.
- 04
Test
We test that the program works as designed: sample testing of alerts and dispositions, test-name runs against the matching logic, and findings with owners and dates that your board, examiner and bank partner can follow.
The Testing Discipline Behind This Practice
Anonymized engagements reflecting the scope and impact of our work. Both are BSA/AML testing and validation engagements, the same discipline we bring to testing sanctions screening.
Top 10 U.S. Financial Institution
Directed BSA/AML testing and MRA validation across a multi-year remediation program. Managed quality assurance across the KYC customer file refresh program evaluating CDD/EDD standards.
Top 25 U.S. Banking Institution
Conducted comprehensive 2LOD compliance testing and transactional reviews across the Banking division. Identified deficiencies and recommended actionable remediation strategies.
“Ethixera brought the depth we expected from a Big 4 firm with the responsiveness and relationship we needed as a growing institution. Their financial crimes advisory work was thorough, practical, and built to last.”
Reading for Sanctions and Screening Teams
What the 2026 BSA/AML exam cycle is signaling to mid-size institutions
Why sanctions screening, list updates and third-party controls have moved to the front of supervisory attention.
2026 BSA/AML exam cycle signalsWhy African VASPs need Western-grade compliance architecture now, not later
For digital asset platforms building AML and sanctions controls for African markets.
Compliance architecture for African VASPsQuestions we hear
Which sanctions lists should we screen against?
Start with where your obligations come from. U.S. persons must comply with OFAC sanctions, so a U.S. business typically screens against OFAC's Specially Designated Nationals and Blocked Persons List and decides, with a written rationale, how it covers OFAC's other sanctions lists.
When customers, counterparties, payout partners or currencies carry a U.K., E.U. or wider international nexus, screening usually extends to the U.K. sanctions list, the E.U. consolidated financial sanctions list and the U.N. Security Council Consolidated List. Bank partners often set their own list expectations in the program agreement, and those can go beyond the legal minimum.
Names are only part of it. Where a sanctions program covers a whole country or region, screening generally needs to look at geography too, such as addresses, payment routing and location data. We document list coverage in your sanctions risk assessment, so the answer to “why these lists” is written down before an examiner asks.
How do we reduce false positives without missing true matches?
Work in order, and test every change. Start with data: incomplete or badly formatted names, missing dates of birth and unused secondary identifiers create alerts that cannot be cleared quickly. Then list management: screening against lists or list segments that do not match your risk adds volume without adding protection.
Next, matching configuration: thresholds, name variants, transliteration and word order, reviewed with above-the-line and below-the-line testing so you can see what a change would stop catching. Last, disposition standards: written rules for which secondary identifiers can discount a match, and governed suppression lists reviewed on a schedule.
Before and after each change, we run test names and variations against the system to show detection still holds. We record the rationale, so an examiner sees risk-based tuning rather than a cut in alert volume.
What is the 50 percent rule?
It is OFAC's guidance that any entity owned 50 percent or more, directly or indirectly, individually or in the aggregate, by one or more blocked persons is itself considered blocked, even if the entity is not named on any list. Aggregation matters: two blocked persons who each own 25 percent of a company together reach 50 percent, and the company is blocked. Indirect ownership matters too, because a blocked entity's own subsidiaries can be caught.
OFAC's rule turns on ownership, not control. OFAC still cautions against dealings with entities in which blocked persons hold a significant ownership interest below 50 percent or exercise control. The U.K. and E.U. regimes apply their own ownership and control tests, which can reach entities through control as well as ownership.
We help you build the ownership analysis: collecting ownership information, tracing chains, aggregating interests, documenting each regime's conclusion and escalating hard cases to your counsel.
Can you test our screening system without replacing it?
Yes, and that is how we work: we test inside the platform you already run, whether it is a vendor system or built in-house.
We trace data from source systems to screening to confirm the right parties and fields are screened, check how quickly list updates reach production, run test names and variations against the matching logic and test thresholds above and below the line. We also confirm the customer base is rescreened when lists change and sample alerts to test disposition quality, timeliness and documentation.
You receive findings, recommended tuning changes and the rationale and evidence for each, written so your examiner, bank partner and board can follow them. If we tuned the system, a different reviewer should perform the independent test of that tuning.
Do you help with voluntary self-disclosures?
We support the process; your counsel leads the disclosure. Under OFAC's Enforcement Guidelines, a voluntary self-disclosure is a significant mitigating factor. The decision to disclose is made by your company with your counsel, and privilege and communications with OFAC and other authorities sit with your counsel.
Working inside that structure, we help reconstruct what happened: how the transaction or customer was missed, a lookback to find other affected activity, the root cause in data, lists, matching or disposition, and the control fixes that prevent a repeat, with evidence that each fix is in place.
Ethixera Advisory is not a law firm and does not provide legal advice.
Need Your Screening Program to Hold Up?
Tell us which lists you screen against, the platform you run, how your alert queue is working and what your examiner or bank partner has asked for. We will scope the program, tuning or testing work that fits.
