Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Sanctions Screening: Five Myths Blocking Your TPRM ProgramThird-Party Risk Management
5 min readFor Third-Party Risk Managers

Sanctions Screening: Five Myths Blocking Your TPRM Program

When Deputy Attorney General Lisa Monaco referred to sanctions enforcement as the "new FCPA" in summer 2022, it marked a significant shift in the DOJ's focus on economic crime. Yet, many third-party risk managers still rely on outdated assumptions that create compliance gaps today.

These myths persist because they're comfortable. Manual processes seem controllable. Quarterly reviews appear thorough. ESG questionnaires look comprehensive on paper. However, OFAC enforcement actions highlight the cost of outdated thinking. A small bank processed 34 payments for SDN-listed individuals because it relied on a 30-day screening cycle deemed insufficient by OFAC.

Here's what you need to stop believing.

Myth 1: Monthly or quarterly sanctions screening meets your obligations

Reality: OFAC expects continuous monitoring, and recent enforcement actions prove it.

A bank in OFAC's Finding of Violation screened new account holders properly but reviewed existing customers only every 30 days. This gap allowed two SDN-listed individuals to receive 34 payments before detection. OFAC's message was clear: periodic screening doesn't prevent prohibited transactions.

In 2023, OFAC designated additional Russian oligarchs and entities supporting the Ukraine war effort throughout the year. If you're screening quarterly, you're blind for 89 days after each designation. A third party could appear on the SDN List in February, and you wouldn't catch it until May, while continuing to process payments, share data, or provide services that violate sanctions.

Daily rescreening is now the baseline OFAC enforces.

Myth 2: Automated screening is only necessary at enterprise scale

Reality: The bank OFAC sanctioned was small, and manual processes failed due to limited resources.

Small organizations often think automation is a luxury for Fortune 500 compliance teams. But OFAC's enforcement action targeted a small financial institution, likely lacking the staff to manually check every customer against daily SDN updates.

Manual screening creates two failure points: human error and resource constraints. Your team can't realistically cross-reference hundreds of vendor names against the SDN List, EU sanctions, UN designations, and sector-specific watchlists daily. Spreadsheets don't update themselves when OFAC adds 50 Russian entities on a Friday afternoon.

Automated solutions cross-reference multiple international sanctions lists and rescreen your entire vendor population daily. Systems like NAVEX RiskRate flag matches immediately, letting your team focus on investigating hits rather than running searches.

If you're managing third-party relationships across borders, manual processes aren't sufficient, regardless of your organization's size.

Myth 3: Sanctions screening is separate from ESG due diligence

Reality: Modern compliance frameworks merge sanctions, human rights, and environmental risks into unified vendor assessments.

Germany's Supply Chain Act (LkSG), effective January 1, 2023, requires companies doing business in Germany to identify and prevent human rights violations and environmental damage in both direct and indirect supplier relationships. You're responsible for forced labor risks in your suppliers' suppliers when you have substantiated knowledge of potential abuses.

This isn't an ESG initiative running parallel to sanctions compliance. It's the same vendor risk assessment expanded to include labor practices, environmental impact, and governance failures. The People's Republic of China's use of forced labor among ethnic minorities and political dissidents creates both human rights violations and potential sanctions exposure.

Your due diligence questionnaires need targeted questions about labor practices, environmental standards, and governance controls, not generic "Do you comply with all applicable laws?" checkboxes. You need verification processes that go beyond accepting a supplier's self-assessment at face value.

Myth 4: If your vendor isn't on the SDN List, you're clear

Reality: Secondary sanctions and indirect support create liability even when your direct counterparty appears clean.

The Biden Administration's sanctions strategy targets not just Russian entities but also parties outside Russia that provide material support to Putin's war effort. OFAC can designate a European logistics company that ships goods to sanctioned Russian oligarchs, even if that company has no Russian ownership.

Your vendor might pass initial screening but have business relationships that create sanctions exposure for you. A software provider with development teams in a sanctioned jurisdiction. A logistics partner that routes shipments through entities on the SDN List. A financial services firm processing payments for designated parties.

This is why geographic risk assessment matters. Identify which vendors operate in high-risk jurisdictions, then apply enhanced due diligence to understand their full business ecosystem. Who are their suppliers? Where do they maintain operations? Which financial institutions do they use?

Myth 5: ESG screening is about reputation management, not legal obligation

Reality: Legislative and regulatory frameworks now impose specific ESG due diligence requirements with enforcement consequences.

The LkSG doesn't suggest companies consider human rights, it requires them to identify, prevent, and minimize violations. It extends those obligations to indirect suppliers when you have substantiated knowledge of abuses. That's not a voluntary corporate social responsibility program. It's a legal mandate with defined obligations.

Other jurisdictions are moving in the same direction. Legislators and regulators expect robust ESG assessment integrated into your due diligence process, not superficial questionnaires you file and forget.

Your contracts need to specify that your ESG policies control, not your vendor's. When you're contracting with suppliers in regions with poor human rights records, this distinction becomes critical. Vague commitments to "ethical business practices" don't protect you. Detailed policies that define prohibited labor practices, environmental standards, and governance requirements do.

What to do instead

Start with automated daily screening against comprehensive sanctions lists. Configure alerts so your team investigates matches immediately, not during next quarter's review cycle.

Revamp your due diligence questionnaires to include specific ESG questions: labor practices, environmental impact assessments, governance structures, and supply chain transparency. Don't accept boilerplate responses. For high-risk vendors, verify claims through proprietary databases, public records, and third-party assessments.

Map your vendor population by geographic risk. Vendors operating in or sourcing from high-risk jurisdictions need enhanced due diligence that examines their full business ecosystem, not just their direct relationship with you.

Build contract language that makes your ESG and sanctions compliance policies controlling. Include audit rights, regular certification requirements, and clear termination provisions for violations.

The era of treating sanctions screening as an annual checkbox exercise ended when OFAC started enforcing continuous monitoring standards. The era of separating sanctions from ESG due diligence ended when the LkSG took effect. Your TPRM program needs to reflect both realities.

Promotional banner for the Pentest Readiness checklist download

You Might Also Like