What Changed in 2025
Regulators issued nearly 4,000 new designations across 265 list updates in 2025. While this is down from 5,674 additions in 2022, the drop in volume hides a bigger shift: sanctions regimes are no longer aligned. The EU and UK increased sanctions activity by 46% and 175% respectively, while the Office of Foreign Assets Control (OFAC) reduced net additions by about 50%. This isn't a delay in policy coordination; it's a structural divergence driven by different geopolitical priorities. Russia-related designations made up 41% of EU and UK list updates, while Iran accounted for 48% of OFAC net additions. The United Nations relisted 121 individuals and entities, marking one of its most significant actions in years.
Your compliance program was likely built for a world where major jurisdictions moved together, even if timing varied. That world no longer exists.
Key Findings
Geographic Fragmentation is Structural. The EU targeted entities in Hong Kong, Türkiye, UAE, and across Asia under 2025 Russian sanctions packages. Russia-related designations accounted for 88% of net additions to the EU list and 66% of UK net additions. If you're only screening against OFAC lists, you're missing most EU and UK enforcement priorities.
Screening Baselines Are Insufficient. EU and UK authorities focused on Russia's shadow fleet and sanctions evasion networks. These programs target network relationships, ownership structures, and indirect exposure risks that aren't captured by simple name-matching. You need transaction monitoring and enhanced due diligence to detect evasion attempts that exploit jurisdictional gaps.
Policy Priorities Diverge by Design. OFAC expanded Iran coverage around oil exports, defense capabilities, and regional influence. The EU and UK concentrated on Russian evasion networks. This isn't a coordination lag. Regulators are building modular, targeted programs responsive to their own foreign policy objectives. Your controls must interpret multiple regulatory lenses simultaneously.
Cross-Border Operations Face Compounding Risk. If you operate in multiple jurisdictions, you're managing obligations that increasingly contradict each other in scope, timing, and enforcement approach. A customer relationship that's compliant under one regime may trigger red flags under another. Your escalation protocols need jurisdiction-specific logic, not global defaults.
What This Means for Your Team
Your screening system was designed for volume, not complexity. It flags exact matches and close variants but doesn't assess whether a Turkish logistics company with no direct list match is part of a Russian evasion network that EU regulators designated last month.
Your compliance framework likely treats sanctions as a binary check: listed or not listed. That approach fails when regulators target networks, beneficial ownership chains, and entities operating through third countries. You're now managing exposure risk, not just list matches.
Your governance model probably assumes that major jurisdictions will eventually converge. They won't. The EU will continue prioritizing Russian sanctions. OFAC will maintain focus on Iran. The UK will balance both while managing post-Brexit policy independence. Waiting for alignment means accepting gaps in your control environment.
Action Items by Priority
Implement Jurisdiction-Specific Screening Logic Immediately. Configure your screening system to apply EU, UK, OFAC, and UN lists based on transaction geography and counterparty location. A Hong Kong entity requires different screening parameters than a UAE entity, even if both are flagged for Russian sanctions evasion. If your current platform can't support multi-jurisdictional logic, escalate that limitation now.
Build Enhanced Due Diligence Triggers for Network Exposure. Develop red flags for entities operating in sectors targeted by evasion programs: shipping, logistics, energy trading, dual-use technology. Train your team to investigate beneficial ownership, not just direct matches. If a counterparty has Russian shareholders, Turkish operations, and UAE banking relationships, that pattern warrants investigation regardless of list status.
Establish Cross-Functional Sanctions Intelligence. Your compliance team can't interpret geopolitical shifts alone. Bring in legal, risk, and business unit leaders quarterly to assess how diverging sanctions affect your operations. IT must participate because your monitoring systems need to adapt in real time, not after annual platform reviews.
Map Your Exposure by Jurisdiction and Counterparty Type. Identify which business lines operate across EU, UK, and US jurisdictions. Document which customer segments present network risk: energy traders, shipping intermediaries, technology suppliers. Quantify how many relationships would require re-screening if you applied all three regimes simultaneously. That gap is your current exposure.
Pressure-Test Your Escalation Protocols. Run a tabletop exercise where a customer relationship is compliant under OFAC rules but triggers EU sanctions for network involvement. Who makes the decision? How quickly can you act? If your protocol assumes jurisdictional alignment, it will fail under real conditions.




