Who is in scope?
The Sanctions Monitoring Board has issued the Implementing Article 32 – Sanctions Compliance Requirements, providing legally binding guidance on the internal procedures, policies and controls expected for compliance with Article 32 of the National Interest (“Enabling Powers”) Act (“NIA”).
The Guidance Note applies to the persons, entities or bodies listed in Schedule I (“Operators”), which currently largely reflects the categories of “subject persons” under the PMLFTR.
What does Article 32 require?
Article 32 requires Operators to establish a Sanctions Framework covering sanctions risk assessment, sanctions customer due diligence and screening, ongoing monitoring, freezing and reporting, tipping-off controls, policies and procedures, record-keeping, reliance and outsourcing, training, systems and governance. The main pints of the guidance have been listed below:
1. The Sanctions Risk Assessment
Operators are required to carry out an enterprise-wide Sanctions Risk Assessment (“SRA”) covering all relevant activity lines. The SRA should identify, assess and document the sanctions risks arising from the Operator’s business model, clients, products, services and transactions, and inform the design of proportionate controls. While this SRA may be integrated within the ML/FT business risk assessment, Operators must ensure that the sanctions risks are properly identified, assessed, documented, and mitigated.
2. AML/CFT CDD ≠ Sanctions CDD
One of the key points for Operators is that sanctions controls and AML/CFT controls are not interchangeable. Although the processes may overlap, they have different legal objectives and requirements.
Under AML/CFT rules, beneficial owners are generally identified using a 25% ownership threshold. For sanctions purposes, however, a different test applies: an entity may be subject to restrictive measures where one or more designated persons collectively own 50% or more of the entity, or where a designated person otherwise exercises control over it.
AML/CFT beneficial ownership information can support sanctions compliance and provides a useful starting point. However, the 25% AML/CFT threshold is not sufficient on its own.
Importantly, sanctions ownership assessments are not limited to natural persons. Legal persons within the ownership structure must also be considered, including legal persons holding 50% or more of the shares or ownership rights in an entity.
3. When does Sanctions CDD start?
Sanctions CDD should be completed before an Operator establishes a business relationship or carries out a transaction, irrespective of the transaction value. Operators should identify and assess the relevant parties, understand ownership and control structures, conduct sanctions screening and consider the context and objective of the relationship or transaction.
4. Who actually needs to be screened?
This is broader than simply screening the client. Operators should identify all parties associated with the relationship or transaction, which may include the client, parties on whose behalf the client is acting, beneficial owners and persons exercising control and, where relevant, intermediaries, agents and counterparties.
The Guidance states that Operators should ordinarily screen, at a minimum, the client, beneficial owners and persons exercising control. Other parties should be screened where their involvement may create sanctions exposure.
5. What happens when screening identifies a designated person?
The Guidance identifies three possible screening outcomes:
- No confirmed match.
The Operator may proceed with the next steps of the sanctions due diligence process. - A designated person is identified, but the ownership or control thresholds are not met.
The Operator may, depending on the circumstances, proceed where no sanctions prohibitions apply, while considering the associated sanctions risk. - A designated person is identified, and the relevant ownership or control thresholds are met.
The Operator must not proceed with the relationship or transaction and must comply with the applicable freezing and reporting obligations.
- No confirmed match.
Where a person who controls the client is a designated person, the Operator must not proceed with the relationship or transaction. This applies even where the designated person does not meet the ownership threshold, as control over the entity is sufficient and is not subject to thresholds. Operators should therefore assess both ownership and control when determining whether sanctions measures apply.
6. Sanctions Customer Risk Assessment (“CRA”).
Once sanctions screening has been completed, Operators should assess the level of sanctions risk associated with the client through a Sanctions Customer Risk Assessment (“CRA”). The Operator may utilize a single risk rating model for both ML/FT and sanctions purposes, however this will result in a client risk rating that encompasses both financial crime risk and sanctions risk. The Guidance states that carrying out a standalone sanctions CRA may facilitate the Operator’s ability to clearly determine the exposure of the client to risks of sanctions breaches or circumvention of restrictive measures.
7.When is Enhanced Due Diligence required?
If a Client has been identified as posing a high risk of sanctions risk, more intensive due diligence is required. Enhanced Due Diligence (“EDD”) is also required where there are material connections to a jurisdiction subject to restrictive measures or associated with sanctions circumvention, where the ownership or control structure is complex, opaque or unusually layered or there is uncertainty as to whether a designated person may hold an ownership interest in or exercise control over the client or another relevant party.
8. Don’t overlook adverse media
The Guidance also addresses adverse media as a potential sanctions risk indicator, including potential indirect ownership or control by designated persons or connections to third parties involved in sanctions breaches or circumvention.
9. Sanctions CDD does not stop at onboarding
Ongoing monitoring should include, at a minimum:
- Repeating sanctions screening
- Keeping CDD information up to date
- Transaction monitoring
- Reviewing the customer risk rating
Operators should also re-screen relevant parties when sanctions lists are updated, new information becomes available, or changes occur in the relationship or transaction.
10. What happens when there is a confirmed sanctions hit?
Where a situation constitutes, or may constitute, a breach of sanctions, the relevant transaction must not proceed. Where a match with a designated person, entity or body is confirmed, relevant funds or economic resources must be frozen without delay, and confirmed matches must be reported to the SMB without delay.
Operators are prohibited from informing clients or third parties in advance that a freezing measure is to be applied.
What does this mean for existing AML/CFT frameworks?
For Operators already subject to AML/CFT requirements, the key message is therefore not simply to add sanctions screening to existing processes, but to ensure that the specific sanctions legal tests and controls are properly addressed within the wider compliance framework.




