Gary Watson discusses the findings in the FCA's review of sanctions, the recent OFSI sanctions fine, and the need for structural change.
When the FCA published its review of sanctions systems and controls in May, the headline numbers were striking enough on their own. Assets frozen in the UK rose from £24.4 billion in 2023-24 to £37 billion the following year. The regulator had, by that point, assessed the sanctions frameworks of more than 150 firms since February 2022. And in its own testing, screening systems correctly identified a sanctioned party 90% of the time on an exact name match, but only 75% of the time where the name appeared in a slightly different form.
Most of the commentary that followed read the report the way it was written; as a message to firms with mature compliance functions, asking them to tighten what they already have. That's a reasonable response if you're a large financial institution. It's a harder brief if you're a small financial services firm that's had to build a full sanctions framework from a blank page.
The no-reliance problem
The legal obligation not to make funds available to a designated person remains with each regulated entity. As a result, agency banking, Banking as a Service (BaaS) setups, and indirect access arrangements (where a Payment Institution (PI), Electronic Money Institution (EMI), or Open Banking provider routes money through a clearing or sponsoring bank using Faster Payments or CHAPS) all produce the same outcome: each party has to screen the same transaction independently, with no shared register that records if and when it has been previously checked.
This means the same payment can be screened three or four times, by firms with no visibility into each other's results, often using different algorithms against the same underlying list(s).
Is this necessary?
None of this is an argument that sanctions screening matters less. In June 2026, OFSI (Office of Financial Sanctions Implementation) issued a penalty of more than £1m against Sabre Global Technologies Limited (SGTL). This is the UK's largest fine for a breach of Russian financial sanctions since the 2022 invasion of Ukraine, and its first penalty specifically for a circumvention offence. SGTL continued giving Ural Airlines, a Russian carrier designated in May 2022, access to its booking and payment systems for seven months after the designation took effect. Once payments to SGTL's UK bank were blocked on sanctions grounds, the firm didn't stop; rather, it explored routing future settlements through a non-UK account instead.
This is a good illustration of why duplicated, disconnected screening isn't just inefficient. A payment block at an individual bank stops that specific transaction, but it does not automatically halt the broader commercial activity or freeze alternative routes. Because there is no shared network, a block by one institution leaves other entities unaware that a sanction concern has been triggered elsewhere.
The case for change here has never been that sanctions controls should be lighter. It's that an architecture built around three or four independent, unconnected checks isn't obviously the best way of catching that, at a moment when both the enforcement and the penalties are this visible.
Why duplication persists
Three further elements of the current screening regime keep this duplication in place:
- Strict liability laws: enacted via the Economic Crime (Transparency and Enforcement) Act 2022, this eliminated the requirement for OFSI to prove a business knew or suspected a breach was occurring. Proving a breach took place on the balance of probabilities is now enough, forcing firms to act with extreme caution.
- The absence of a safe harbour: while OFSI views good-faith due diligence as a mitigating factor, there is no mechanism allowing a firm to point to another regulated entity's screening and treat its own obligation as discharged. The only legal safety net is to screen everything independently.
- Risk appetite variance: as highlighted by the FCA's reviews, the calibration and testing of screening systems vary wildly across the market. The practical consequence is that the exact same name on the same payment can effortlessly clear one firm's system and trigger a hard stop at the next.
When strict liability, no safe harbour, and inconsistent calibration are put together, the duplication stops looking like inefficiency and starts looking like firms have no other option.
The risk of mutual reliance
Would a mutual reliance framework be beneficial? It's certainly not straightforward, otherwise it would've already been addressed. The FCA's own report includes a case study of a firm whose external screening system became unavailable, with no contingency arrangements in place, leaving thousands of payments queuing unscreened. Build a mutual reliance framework around a small number of upstream screeners, and that kind of outage stops being one firm's problem and becomes every downstream participant's problem simultaneously. Combine this with strict liability and it's easy to see why there's not been any meaningful push to formalise screening reliance for sanctions.
All that said, risks can be managed. Contingency screening, with clear SLAs after an outage, can be incorporated into governance models and minimum calibration standards between firms can be set, with auditing access rights. Could there exist the possibility of a downstream firm in a closed chain placing some reliance on an upstream firm's screening?
What this means in practice
We are where we are. Until the framework evolves, a smaller financial services firm must be able to evidence four core things:
- a risk assessment detailing documented reasoning for its screening perimeter;
- a testing record showing when the screening configuration was last calibrated;
- an alert-handling SLA with a clearly defined escalation route; and
- a contingency plan outlining what happens if the screening system itself goes down.
No firm, however small, can design its way out of doing the screening itself. However, the system would be vastly improved if the sanctions regime stopped forcing multiple participants in a single domestic chain to replicate the exact same process, simply because the current regulatory architecture fails to accommodate a shared alternative.