Sanctions compliance has become a boardroom priority, yet many third-party risk programs still operate on outdated assumptions. These assumptions were formed before the Russian Federation's invasion of Ukraine, which led to what Deputy Attorney General Lisa Monaco described as "unprecedented intensity" in enforcement. The gap between what compliance teams think works and what regulators now expect creates liability exposure that no policy document can fix.
These myths persist because they worked in less demanding environments. Manual quarterly screenings were adequate when sanctions lists changed infrequently. Periodic reviews sufficed when the DOJ treated violations as minor infractions. That world ended when OFAC began updating restrictions on Russian crude oil maritime transportation and the DOJ established Task Force KleptoCapture to prosecute sanctions evasion.
Here's what your team likely believes about sanctions screening, and what the current enforcement environment actually demands.
Myth 1: Quarterly Manual Screening Meets Regulatory Expectations
Reality: OFAC and other sanctions authorities update their lists continuously. Enforcement actions have shown that even short intervals between screenings create violation windows. One recent case highlighted how the gap between periodic manual reviews allowed prohibited transactions to proceed despite the counterparty's addition to the SDN List.
When OFAC expanded Russia sanctions to include maritime transportation of crude oil below specific price caps, companies relying on quarterly checks had no way to identify newly restricted activities until their next scheduled review. By then, contracts were signed and services rendered.
Automated continuous screening is essential. It's the minimum response to regulators who update restrictions faster than your calendar reminders. If your vendor risk platform doesn't alert you within 24 hours of an SDN List update affecting your counterparties, you're operating with systematic blind spots.
Myth 2: List-Based Screening Catches All Sanctions Risk
Reality: Not all sanctions prohibit transactions with designated entities. Many prohibit specific conduct regardless of who's involved. OFAC's restrictions on financial transactions, export controls from the Bureau of Industry and Security, and prohibitions on certain services don't appear on any screening list.
Consider the maritime transportation restrictions OFAC recently imposed. Your vendor might be a legitimate shipping company with no SDN List presence, but if they transport Russian crude oil below the price cap, your contract with them violates sanctions regulations. No automated screening tool flags this because the violation stems from the activity itself, not the entity's designation status.
Enhanced due diligence is non-negotiable. For transactions with a Russian Federation nexus or involvement in sanctioned sectors, you need documented inquiry into what the vendor actually does, not just who they are. Your due diligence questionnaire should explicitly ask about sanctioned activities, and your contract review process should flag prohibited services before signatures happen.
Myth 3: Sanctions Compliance Is a Legal Department Problem
Reality: The compliance function owns sanctions risk just like it owns anti-bribery risk under the Foreign Corrupt Practices Act. Monaco's comparison wasn't rhetorical. It signaled that the DOJ expects the same systematic controls, documented procedures, and executive accountability for sanctions that it's demanded for FCPA compliance for decades.
This means your third-party risk management program needs sanctions-specific procedures that procurement, finance, and operations teams actually follow. When a business unit wants to onboard a new vendor, the workflow should automatically trigger sanctions screening before contract execution. When treasury processes international payments, the system should block transactions to sanctioned jurisdictions without requiring manual intervention.
If sanctions review happens only when legal gets involved, you've built a control that depends on someone remembering to escalate. That's not a control. That's hope with documentation.
Myth 4: Clean Screening Results Mean You're Protected
Reality: Demonstrating good faith effort matters more than perfect outcomes in enforcement proceedings. A clean screening result protects you only if you can show consistent application of risk-based procedures. If your vendor passes automated screening but you never documented enhanced due diligence for a high-risk transaction, regulators will question whether you actually understood the sanctions landscape or just ran a tool.
The enforcement leniency Monaco referenced goes to companies that show systematic attention to sanctions risk. That means documented risk assessments that explain why certain vendors warranted enhanced review. It means evidence that your screening protocols actually run before transactions occur, not after. It means your Vendor Risk Profile for counterparties in sanctioned sectors includes specific sanctions risk analysis, not just generic compliance checkboxes.
Your screening vendor's clean report is evidence, not absolution. The question in an enforcement action isn't whether your tool worked. It's whether your program demonstrated reasonable care given your specific risk exposure.
Myth 5: We Don't Need This Because We Don't Do Business in Russia
Reality: Sanctions against the Russian Federation target both direct relationships and indirect facilitation. If your logistics provider uses Russian shipping companies, if your software vendor has development teams in Moscow, if your distributor re-exports to sanctioned jurisdictions, you have Russian Federation nexus whether you recognize it or not.
The coordinated international response to Ukraine includes UK and EU measures that create compliance obligations beyond OFAC's reach. A European subsidiary contracting with a Russian-owned entity might violate EU sanctions even if OFAC doesn't prohibit the relationship. Your third-party risk program needs to account for the sanctions regimes that apply to each of your operating entities, not just U.S. regulations.
More broadly, the current enforcement environment around Russia sanctions previews how regulators will approach future geopolitical restrictions. The infrastructure you build now for Russian Federation sanctions screening becomes your template for responding to the next coordinated international response, wherever it targets.
What to Do Instead
Start with automated continuous screening as your baseline control. If you're still running manual quarterly checks, allocate budget to a reputable sanctions screening provider now. The cost of the tool is a rounding error compared to the penalties from violations that occur between manual reviews.
Build enhanced due diligence protocols for high-risk transactions. Define what triggers enhanced review: sanctioned sectors, Russian Federation nexus, complex ownership structures, high-value contracts. Document the specific inquiries you make and the evidence you collect. If you lack internal resources for this analysis, engage a compliance solutions provider or law firm with sanctions expertise.
Integrate sanctions screening into your operational workflows, not just your onboarding process. Payment systems should validate counterparties before releasing funds. Contract management systems should require clean screening before routing agreements for signature. Make it technically difficult to transact with a vendor who hasn't cleared sanctions review.
Finally, treat this as an ongoing program requirement, not a project. The sanctions landscape changes faster than your annual compliance calendar. Your third-party risk management program needs the infrastructure to respond within days, not quarters.




