Do You Legally Need Sanctions Screening? A Global Guide
Sanctions prohibitions bind almost everyone; screening-programme obligations don't. A jurisdiction guide covering the US, UK, EU, Singapore, UAE, and India.

Sanctions law works on two levels that get conflated constantly. Sanctions prohibitions (do not deal with a designated person) apply to almost everyone with any connection to a sanctioning jurisdiction, no registration or licence required. Sanctions screening programme obligations (you must actively check customers against the lists and document that you did) apply only to businesses a regulator has designated as "obliged entities." Most businesses without a formal screening mandate still carry real exposure, because the prohibition reaches them even when the programme requirement doesn't.
This guide is current as of 14 August 2026 and covers the United States, United Kingdom, European Union, Singapore, the United Arab Emirates, and India.
Do I legally need sanctions screening?
It depends which of two separate questions you're asking. If the question is "can I be liable for dealing with a sanctioned person," the answer is almost always yes, regardless of your business type: sanctions prohibitions bind broadly. If the question is "am I required to run a documented screening programme," the answer depends on whether your sector is named in that jurisdiction's AML or sanctions regulations as a regulated or "obliged" entity. Banks and payment institutions almost always are; a domestic retailer usually isn't.
The practical consequence: a business with no formal screening mandate can still commit a sanctions violation the first time it unknowingly deals with a designated party. Screening is how regulated and unregulated businesses alike avoid that outcome. The law just doesn't force the unregulated ones to prove it in writing.
What's the difference between a sanctions prohibition and a sanctions screening obligation?
A prohibition tells you what you can't do; a programme obligation tells you how you must prove you're not doing it. OFAC states plainly that "all U.S. persons must comply with OFAC regulations, including all U.S. citizens and permanent resident aliens regardless of where they are located, all persons and entities within the United States, [and] all U.S. incorporated entities and their foreign branches" [OFAC FAQ 11]. Nothing in that sentence mentions being a bank.
FATF's own standards draw the same line at the international level. Recommendation 6, covering targeted financial sanctions, requires countries to freeze funds "owned or controlled by a designated person or entity": a duty that falls on all natural and legal persons in the country, not a defined regulated population. Recommendation 10 is customer due diligence for financial institutions (identity, verification, risk-rating), extended to designated non-financial businesses and professions (DNFBPs) via Recommendation 22 [FATF Recommendations]. That CDD programme is where screening usually lives in practice, but the freeze duty itself is Rec 6, not Rec 10. Recommendation 1 requires that CDD measures be applied "using a risk-based approach" (the source of the flexibility regulated firms rely on to calibrate their programmes).
Which regulator and law applies in each jurisdiction?
| Jurisdiction | Core statute(s) | Regulator(s) | Liability standard | Maximum penalty |
|---|---|---|---|---|
| United States | IEEPA (50 U.S.C. §1701 et seq.); Bank Secrecy Act | OFAC (sanctions); FinCEN + federal banking regulators (AML programme) | Civil liability is strict: no knowledge or intent required [OFAC FAQ 65] | $377,700 per violation, or 2× the transaction value, whichever is greater (2025-adjusted; unchanged into 2026) [Federal Register, 90 FR 3687, 15 Jan 2025; Federal Register, 7 Jul 2026] |
| United Kingdom | Sanctions and Anti-Money Laundering Act 2018; Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017 | OFSI (HM Treasury, sanctions); FCA and other supervisors (AML) | Two-track: civil monetary penalties are strict liability for breaches after 15 June 2022; criminal prosecution still requires "reasonable cause to suspect" [OFSI, 8 Jun 2022] | Civil: the greater of £1 million or 50% of the estimated value of the funds [OFSI enforcement guidance]. Criminal: up to 7 years' imprisonment. OFSI has announced an intended increase to £2 million or 100% pending legislation; as of 14 August 2026 the statutory cap is still £1 million / 50% |
| European Union | Country/regime-specific restrictive-measures Regulations (directly applicable); Directive (EU) 2024/1226 (criminalisation); AML Regulation (EU) 2024/1624 from 10 Jul 2027 | National authorities per Member State; AMLA (from 2028, direct supervision) | Criminalisation requires intentional conduct (narrower "serious negligence" standard only for specific export-item breaches) [Directive (EU) 2024/1226] | Minimum maxima: Member States must set a maximum of at least 5 years' imprisonment for listed offences above value thresholds. Legal persons: fines not less than 5% of worldwide turnover or €40 million, whichever the Member State chooses as its method [Directive (EU) 2024/1226] |
| Singapore | United Nations Act; MAS Notice 626 (banks); PSN01/PSN02 (payment and digital-token services) | Monetary Authority of Singapore | Regulatory/administrative enforcement of screening-programme failures; no MAS statement labelling it "strict liability" in the way OFAC or OFSI do | Case-by-case composition fines and licence conditions under the MAS Act; no single published maximum figure for screening-programme breaches |
| United Arab Emirates | Federal Decree-Law No. 20 of 2018; Cabinet Decision No. 10 of 2019; Cabinet Decision No. 74 of 2020 (targeted financial sanctions) | CBUAE (Licensed Financial Institutions); Ministry of Economy (DNFBPs) | Explicitly strict liability: CBUAE's own regulation is titled "Regulation to Impose Financial Sanctions for Strict Liability Violations" [CBUAE Circular 22/2021] | TFS: imprisonment or a fine of AED 50,000 to AED 5,000,000 per violation for any natural or legal person [Cabinet Decision No. 74 of 2020]. DNFBP administrative fines sit on a separate schedule under Cabinet Resolution No. 71 of 2024 |
| India | Prevention of Money Laundering Act, 2002 (PMLA); Unlawful Activities (Prevention) Act, 1967, s.51A | FIU-IND (reporting); RBI, SEBI, IRDAI (sectoral AML rules) | Compliance-failure penalties under PMLA s.13 attach on proof of the failure; PMLA does not publicly label this "strict liability" the way the US, UK, and UAE regimes do | ₹10,000 to ₹1,00,000 per failure under PMLA s.13 [PMLA, s.13] |
Two things stand out. First, "strict liability" is not universal: it is an explicit, named standard in the US, UK (civil track), and UAE, while the EU's 2024 directive deliberately requires intent or negligence, and Singapore and India enforce compliance failures without using that specific label. Treating every regime as strict liability overstates the EU, Singapore, and India positions; treating none of them as strict understates the US, UK, and UAE. Second, penalty structures aren't comparable on a single axis: some cap per violation, some scale with transaction value, and the EU's legal-person penalty scales with global turnover, which can dwarf every other figure on this list for a large multinational.
Is sanctions liability really strict? Do I have to prove intent?
In the US, UK, and UAE: yes, for civil/administrative purposes, and no proof of intent is required. OFAC amended FAQ 65 on 13 November 2024 to confirm a person "may be held civilly liable even if such person did not have knowledge that it was engaging" in a prohibited transaction [OFAC FAQ 65]. Intent still matters for OFAC: it moves a violation between the "egregious" and "non-egregious" tiers of its penalty matrix, which changes the size of the fine, not whether one is owed [31 CFR Part 501, Appendix A].
The UK reached the same civil-liability position more recently and more deliberately. Before June 2022, OFSI had to show a person "knew, suspected, or had reasonable cause to suspect" a sanctions breach. The Economic Crime (Transparency and Enforcement) Act 2022 removed that requirement for civil monetary penalties: OFSI now only has to establish, on the balance of probabilities, that a breach occurred [OFSI, 8 June 2022]. Criminal prosecution under the same regime, however, still runs on the older "reasonable cause to suspect" standard: a UK sanctions breach can be civilly punished with no fault at all, and separately, criminally prosecuted only where fault existed.
The EU took the opposite path. Its 2024 harmonising directive requires Member States to criminalise sanctions breaches specifically when committed intentionally, with a narrower serious-negligence standard reserved for certain export-control conduct [Directive (EU) 2024/1226]. Singapore and India enforce screening-programme failures as regulatory or statutory compliance breaches, but neither jurisdiction's public guidance uses the "strict liability" label. That's worth confirming with local counsel rather than assuming either standard by analogy to the US or UK.
Which business types are legally required to run sanctions screening?
Banks are covered everywhere in this guide; the picture fragments fast after that. The table below marks where a sector is explicitly named as a regulated or "obliged" entity for AML/sanctions-screening purposes under that jurisdiction's own law.
| Business type | US | UK | EU | Singapore | UAE | India |
|---|---|---|---|---|---|---|
| Banks | Named: BSA "financial institution" [31 U.S.C. §5312] | Named: MLRs 2017, reg. 8 | Named: AMLR obliged entity | Named: MAS Notice 626 | Named: CBUAE LFI | Named: PMLA "reporting entity" |
| Payment institutions / EMIs | Named as money services businesses | Named explicitly in reg. 8 | Named as financial institutions | Named: PSN01 | Named as LFI | Named: RBI-regulated payment operators |
| Crypto / VASPs | Named via FinCEN's 2019 MSB guidance | Named: cryptoasset exchange & custodian wallet providers | Named: CASPs under MiCA, via AMLR | Named: PSN02, digital payment token services | Named explicitly as VASPs | Named: notified as reporting entities for virtual digital assets |
| Lenders / NBFCs / finance companies | Named: "loan or finance company" [31 U.S.C. §5312]; FinCEN implementation has lagged for some of this category | Named as financial institutions | Named as financial institutions | Named as regulated finance companies | Named as LFI | Named as RBI-regulated financial institutions |
| Insurers | Named explicitly [31 U.S.C. §5312] | Named: insurance undertakings, esp. life | Named: life insurance intermediaries | Named under a separate MAS insurance notice | Named as LFI | Named: IRDAI-regulated insurers |
| Marketplaces / platforms (as such) | Not named as a category; covered only if a listed function applies | Not named as a category | Not named as a category | Not named as a category | Not named as a category | Not named as a category |
| Exporters | Separate regime: EAR/ITAR restricted-party screening, not BSA/AML | Separate: UK strategic export controls | Separate: EU dual-use Regulation | Separate export-control framework | Separate: UAE export-control rules | Separate: India's export-control regime |
| Law firms / accountants (DNFBPs) | Not named in the BSA's "financial institution" list | Named: independent legal professionals, external accountants, TCSPs | Named: DNFBP categories | Not independently confirmed here; check MAS/Law Society guidance directly | Named: auditing/accounting firms, TCSPs | Named: notified designated businesses/professions |
Three gaps are worth calling out explicitly, because each is where "we're not a bank, so this doesn't apply to us" reasoning breaks down:
- Marketplaces and platforms are not named as a category anywhere in this table, but a platform that facilitates payments, holds customer funds, or operates a wallet frequently falls into the payment-institution or money-transmitter category on function, not on label. The determination is activity-based, not name-based, in every jurisdiction reviewed.
- Exporters run a separate compliance track entirely: restricted-party and denied-persons screening under export-control law, distinct from AML/sanctions-programme obligations. A business can be fully AML-compliant and still violate export controls, or vice versa.
- US law firms and accountants are conspicuously absent from the Bank Secrecy Act's "financial institution" definition, unlike their counterparts in the UK, EU, and UAE, where legal and accounting professionals are named DNFBPs. A US law firm handling a client's funds through a company structure sits outside the BSA's reporting-entity list even though a UK or UAE firm doing the same work would not.
What about the exporter and crypto edge cases specifically?
Crypto is now explicitly covered in every jurisdiction in this guide: the "unregulated crypto" era is over as a screening matter. All six regimes here name virtual-asset or digital-token service providers as regulated entities, most recently the EU's AMLR bringing MiCA-licensed CASPs into the same obliged-entity category as banks. Exporters, by contrast, were never inside the AML/sanctions-programme framework in the first place; their restricted-party screening obligation comes from export-control law (EAR and ITAR in the US; the dual-use Regulation in the EU; equivalent regimes elsewhere), which runs on its own list set and its own penalty structure. Businesses doing both (say, a fintech exporting licensed software) need both compliance tracks, not one covering the other.
What does "adequate" screening look like when there's no single prescriptive standard?
There generally isn't one: regulators deliberately require a risk-based programme instead of a fixed checklist, and "risk-based" is not the same as "optional." FATF's Recommendation 1 requires that AML/CFT measures be "commensurate with the risks identified," explicitly permitting simplified measures where risk is demonstrably low and requiring enhanced measures where it's high [FATF Recommendations, R.1]. Recommendation 10 applies the same logic to customer due diligence specifically: financial institutions must "determine the extent of such measures using a risk-based approach" [FATF Recommendations, R.10].
In practice, "adequate" for a screening programme means being able to show, to an examiner, the reasoning behind your choices: which lists you screen (and why those and not others, see our comparison of OFAC, EU, UN, and UK list coverage), how often you re-screen, what match threshold you use and why, and how alerts get reviewed and closed. A risk-based programme that can't produce that reasoning on request is functionally indistinguishable, to a regulator, from no programme at all.
Frequently asked questions
Do I need sanctions screening if I'm not a regulated financial institution? You may not have a programme obligation, but the underlying prohibition on dealing with a sanctioned party almost certainly still applies to you if you have any nexus to that jurisdiction: incorporation, staff, customers, or currency flows. Screening is how you avoid the prohibition violation even without a formal mandate to run a programme.
Is a US company required to screen against EU or UK lists? Only if it has a nexus to that jurisdiction, such as an EU or UK subsidiary, staff, customers, or business conducted in part there. A purely domestic US business with no such connection isn't bound by EU or UK sanctions law, though it remains fully bound by US law regardless.
Does using USD payment rails create sanctions exposure even without a US entity? Yes. Clearing transactions in US dollars routes them through the US financial system, which is generally sufficient to bring a non-US business within OFAC's reach for that transaction, regardless of where the business is incorporated or operates.
Is crypto exempt from sanctions screening obligations? No. Every jurisdiction covered here (the US, UK, EU, Singapore, UAE, and India) now names virtual-asset or crypto-asset service providers as regulated entities subject to AML and sanctions-screening obligations, most recently formalised in the EU's AML Regulation.
Is this legal advice? No. This article describes publicly available regulatory frameworks as of 14 August 2026 for informational purposes. It is not a substitute for advice from qualified counsel in the jurisdictions relevant to your business: several of the standards above (particularly Singapore's and India's liability doctrine, and the UK's civil penalty figures) rest on regulator guidance and enforcement practice that changes without much notice.
Citations
- OFAC, FAQ 11: Who must comply with OFAC regulations?, https://ofac.treasury.gov/faqs/11
- OFAC, FAQ 65, updated 13 November 2024, https://ofac.treasury.gov/faqs/65
- Economic Sanctions Enforcement Guidelines, 31 CFR Part 501, Appendix A, https://www.ecfr.gov/current/title-31/subtitle-B/chapter-V/part-501/appendix-Appendix%20A%20to%20Part%20501
- Federal Register, Inflation Adjustment of Civil Monetary Penalties, 90 FR 3687, 15 January 2025, https://www.govinfo.gov/content/pkg/FR-2025-01-15/html/2025-00786.htm
- Federal Register, No Adjustment to Civil Monetary Penalty Amounts, 7 July 2026, https://www.federalregister.gov/documents/2026/07/07/2026-13629/no-adjustment-to-civil-monetary-penalty-amounts
- 31 U.S.C. §5312 (Bank Secrecy Act "financial institution" definition), https://www.law.cornell.edu/uscode/text/31/5312
- OFSI, Financial sanctions enforcement and monetary penalties guidance (£1 million or 50% of estimated value), https://www.gov.uk/government/publications/financial-sanctions-enforcement-and-monetary-penalties-guidance/financial-sanctions-enforcement-and-monetary-penalties-guidance
- OFSI, New enforcement powers: a message from Giles Thomson, Director of OFSI, 8 June 2022, https://ofsi.blog.gov.uk/2022/06/08/new-enforcement-powers-a-message-from-giles-thomson-director-of-ofsi/
- Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, regulation 8, https://www.legislation.gov.uk/uksi/2017/692/regulation/8
- Directive (EU) 2024/1226 of 24 April 2024 on the definition of criminal offences and penalties for the violation of Union restrictive measures, https://eur-lex.europa.eu/eli/dir/2024/1226/oj/eng
- European Commission, Anti-money laundering and countering the financing of terrorism at EU level, https://finance.ec.europa.eu/financial-crime/anti-money-laundering-and-countering-financing-terrorism-eu-level_en
- Monetary Authority of Singapore, Notice 626: Prevention of Money Laundering and Countering the Financing of Terrorism – Banks, revised 30 June 2025, https://www.mas.gov.sg/regulation/notices/notice-626
- CBUAE, Regulation to Impose Financial Sanctions for Strict Liability Violations, Circular 22/2021, https://rulebook.centralbank.ae/en/rulebook/regulation-impose-financial-sanctions-strict-liability-violations
- UAE Cabinet Decision No. 74 of 2020 (targeted financial sanctions; TFS penalty range), via Ministry of Economy DNFBP guidance, https://www.moet.gov.ae/en/-/does-your-company-fall-under-the-dnfbp
- UAE Cabinet Resolution No. 71 of 2024 (DNFBP administrative fines schedule), https://uaelegislation.gov.ae/en/legislations/2546
- Prevention of Money-Laundering Act, 2002, s.13, https://indiankanoon.org/doc/893415/
- FATF, The FATF Recommendations (Recommendations 1, 6, 10, 22), https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
Knowing your exposure is step one
Working out which obligations apply to your business is the easy half: the harder, ongoing part is running a screening and monitoring programme that can defend its decisions two years later.
DeRisk Hub screens against dozens of sanctions, export-control, and PEP list sources, re-screens automatically on every list update, and writes every decision to an immutable audit trail. See what sanctions screening involves, start your free trial, or go to DeRiskHub.com.
This article is informational and does not constitute legal advice. It describes publicly available regulatory frameworks as verified against regulators' own published material on 14 August 2026; sanctions and AML law changes frequently and varies by fact pattern; confirm your specific obligations with qualified counsel before relying on anything above.