Sanctions list check automated: EU requirements, tools, chain of documents
For many companies, an automated sanction list check is mandatory, not optional. This overview shows which EU regulations set the framework, how the consolidated list is linked and how you can document hits in an audit-proof manner.
The EU maintains around 40 thematic sanctions regimes with over 2,500 listed natural persons and organisations, supplemented by lists of goods and sectors in the regulations on Russia, Belarus, Iran, Syria, North Korea and other addressees. Anyone who runs a company in Germany must comply with these requirements, even if they are not active in traditional foreign trade. Regulation (EU) 2580/2001 on combating terrorist financing and the respective country regulations, such as (EU) 833/2014 on Russia, prohibit the provision of economic resources to listed persons or organisations. A violation is punishable under Section 18 AWG with a prison sentence of up to ten years or a fine; legal entities are subject to fines under Section 30 OWiG.
Manual checking against the consolidated EU sanctions list is practically impossible for more than a few customers, suppliers or employees. An automated check with a daily updated data source, hit process and document chain is therefore the state of the art. This article explains the legal obligations, the architectural options, the interfaces to the consolidated EU list, the handling of hits and false hits as well as the integration with the Money Laundering Act, foreign trade law and the money laundering officer's appointment document. Audit-proof, documented, § ...-proof also applies to every sanctions check you carry out today.
Key Takeaways
- The EU sanctions regulations are directly applicable law in Germany; Violations will be prosecuted under criminal law in accordance with Section 18 AWG and fines in accordance with Section 19 AWG and Section 30 OWiG.
- An automated sanctions list check must update the consolidated EU list daily, carry out fuzzy-tolerant name comparisons and document each check in an audit-proof manner with a time stamp, hit and false hit decision.
- If a hit occurs, the business relationship must be frozen immediately, the Bundesbank must be informed and the process must be documented by the money laundering or export control officer; Deadline begins as soon as we become aware of it.
Legal framework: Which regulations bind you
The obligation to check sanctions lists derives from several sources. The first source is the EU sanctions regulations themselves. Regulation (EC) 881/2002 on persons associated with Al-Qaeda, Regulation (EU) 2580/2001 on terrorist financing and the country regulations (EU) 833/2014 on Russia, (EU) 765/2006 on Belarus, (EU) 267/2012 on Iran, (EU) 36/2012 on Syria and others contain a ban on providing funds: It is prohibited to directly or indirectly provide financial resources, economic resources or services to persons, organisations or institutions on the respective list. This results in an obligation to check the consolidated list before each provision.
The second source is the German Foreign Trade Act (AWG) and the Foreign Trade Ordinance (AWV). Section 18 AWG criminalizes violations of EU sanctions, Section 19 AWG provides for fines. The third source is the Money Laundering Act: As part of the increased due diligence requirements under Section 15 of the GwG, sanctions checks are part of customer screening, especially for high-risk countries or politically exposed persons. The fourth source is industry-specific requirements, such as the BaFin circulars for banks and financial service providers. The Money Laundering Officer role covers the AMLA side, supplemented by the interface to the export control officer, who monitors sanctions violations in the foreign trade context. Without a clear allocation of responsibilities, gray zones arise in which those involved watch each other while a hit goes unchecked. In addition, there is the embargo-specific criminal law: Section 17 AWG sanctions intentional violations of arms embargoes with a prison sentence of one to ten years, or longer in particularly serious cases. Negligent violations are also punishable according to Section 18 Paragraph 5 AWG. Any management who delays the introduction of an effective sanction check not only risks fines, but also personal criminal liability. The Bundesbank website provides monthly information about current listing changes; the direct binding nature of the regulations themselves is more than an indication of supervisory practice.
Consolidated EU sanctions list: source and update frequency
The EU publishes a consolidated list of financial sanctions through the Financial Sanctions Files (FSF) of the Directorate-General for Financial Stability, Financial Services and Capital Markets Union. The list is available as an XML file, is usually updated several times a week when listing changes occur, and contains all persons and organisations listed under the EU sanctions regulations. Each entry contains structured fields such as name, aliases, date of birth, place of birth, addresses, passport and ID numbers as well as the listing basis and the date of listing. The data is provided free of charge and an account is not required.
Further lists are also required: the UN sanctions list (if not already implemented into EU law), the OFAC SDN list for US business relationships, the UK HMT sanctions list for business relationships in the United Kingdom, the Swiss SECO list, as well as national lists for certain sectors. An automated solution should keep several lists in parallel, the EU list as a minimum standard, others depending on the business context. The update must be done daily, ideally as a pull job early in the morning before operations start. Others run compliance like a filing cabinet. We run it like software. In the CIVAC workspace, the update logic is mapped automatically and each list version is archived with a time stamp so that later checks can be reconstructed. A list architecture distinguishes between core, secondary and special lists. The core is the EU, UN, OFAC, UK HMT and SECO. Secondary are the lists of friendly third countries that are relevant for certain business relationships. PEP lists, media sanctions lists and adverse media indicators are special and although they are not necessarily prohibited, they do lead to increased care. A version history for each list, with date, file size, hash value and import protocol, belongs in the document chain.
Architecture of an automated sanctions check
An automated sanctions check consists of several components. Firstly, the data source, i.e. the daily updated consolidated list, ideally with version management. Secondly, the master data to be checked: customers, suppliers, beneficial owners, employees, managers, payment recipients, freight recipients. Thirdly, the matching engine, which compares names, dates of birth, addresses and, if necessary, ID numbers with the lists and works in a fuzzy-tolerant manner, i.e. detects spelling variants, transliterations and typos. Fourth, the hit process with review, escalation, decision and documentation. Fifthly, the document storage, which stores every check process with a time stamp, list version, data status and decision history in an audit-proof manner.
The matching engine is the most technically demanding part. Pure string equality comparisons are not sufficient because names occur in different spellings (Cyrillic vs. Latin, with or without patronymic, with or without a hyphen, with different transliterations). Algorithms such as Soundex, Metaphone, Jaro-Winkler or Levenshtein distance, supplemented by alias lists and contextual heuristics, are common. The hits are sorted into confidence classes: certain, probable, possible, unlikely. The threshold values are documented and are regularly calibrated based on false hit rates. A threshold that is too narrow leads to misses, while one that is too wide leads to a flood of false hits and corresponding employee fatigue. A balanced calibration with documented threshold value history is state of the art and should appear in the process description of the internal security measures. Architecture also includes the question of where in the business process the check is carried out. It makes sense to have checkpoints before a new customer is created in the ERP, before every outgoing payment in the treasury system, before every order in purchasing and periodically across the entire master data base. A real real-time check in the transaction prevents a payment to a recently listed recipient from going through unchecked, provided the interface between the payment system and the sanctions list engine is designed consistently.
Hit process: From hit to decision
When the matching engine returns a hit, the actual compliance process begins. Step one is the hit check by a trained employee who analyses the confidence class, the match points and the listing basis. Step two is to clarify the facts: identity comparison with the existing customer data, clarification of aliases, dates of birth and addresses, if necessary direct contact with the customer for clarification. Step three is the decision: false hit (with justification in the file), hit with freezing of the business relationship or escalation to management and money laundering officer.
If a hit is confirmed, the business relationship must be frozen immediately and no payment or delivery may be made. The Deutsche Bundesbank must be informed about the frozen assets in accordance with Article 8 of the respective EU regulation; the Federal Office of Economics and Export Control (BAFA) is involved depending on the sanctions regime. If the Money Laundering Act is involved, a suspicious transaction report is also made to the FIU in accordance with Section 43 of the GwG. The clock starts on awareness. The entire process is documented in the workspace with a time stamp, people involved, documents presented and the decided result. Audit-proof, documented, § 18 AWG-proof. This chain of evidence provides significant relief during subsequent supervisory visits or in criminal proceedings. An important secondary obligation is the internal communication ban, the so-called tipping-off ban according to Section 47 of the GwG: If a suspicious transaction is reported to the FIU or a sanction is escalated, the affected customer may not be informed about the process, otherwise there is a risk of an additional criminal offense. Training the employees involved on the wording and tone of address when addressing customers in the event of a hit prevents operational activism from becoming a second offense. A prepared communication template also belongs in the audit templates.
Sector and goods-based screening: Not just people
The EU sanctions are not limited to lists of people. Numerous regulations contain restrictions on goods and sectors, such as the embargo for dual-use goods according to Regulation (EU) 2021/821, the Russia embargo according to (EU) 833/2014 with extensive lists of goods and technologies, the Iran embargo (EU) 267/2012 with reference to nuclear and missile technology or the Belarus embargo (EU) 765/2006 with restrictions for Wood materials, potassium salts and energy products. Anyone who exports technical goods, software or services must carry out a classification according to goods lists and check whether the specific transaction is subject to approval or prohibition.
An automated solution can support these sector sanctions by comparing product codes (HS code, dual-use list identifier) with the sanctioned goods lists. The prerequisite is the correct classification of your own products. The responsibility for this lies with the company, not with the tool. The Role page at a glance shows which officers can be responsible for which sanctions and export control aspects, from the money laundering officer to the export control officer to management. The auditor calls, the evidence is ready. The audit trail must show that the classification was carried out consciously and with evidence, for example through a substance or product master database with a documented classification decision and person responsible. In addition, there are service sanctions, which have been greatly expanded in recent years. Auditing, legal, consulting and IT services have their own restrictions depending on the destination or country of origin. Anyone who sells a SaaS licence to a customer with a Russian business connection should be aware of the list of prohibited services and take them into account in the sanctions check, supplemented by a clarification as to whether an approval procedure is possible.
Business relationships with third countries and indirect provision
The EU sanctions ban on providing goods applies not only to direct deliveries to listed persons, but also to indirect deliveries via straw people, affiliated companies or trust structures. Anyone who has a customer in a third country whose beneficial owner is a listed person is subject to the ban. The sanctions list often refers to ownership thresholds (typically 50 percent ownership or controlling influence), below which provision remains possible if there is no evidence of a circumvention constellation. The review of the ownership structure is therefore part of the sanctions review and overlaps with the obligation to determine the beneficial owner in accordance with Section 11 of the GwG.
In practice, it has proven useful to integrate beneficial ownership screening into the sanctions review. Sources are commercial registers, transparency registers in accordance with Section 18 GwG, economic and credit databases as well as self-disclosures from the customer. If anything is unclear, increased due diligence is required: additional documentation, management approval, closer monitoring. The appointment certificate, signed, filed, verifiable: This logic applies not only to the agent himself, but also to every management approval of a risky business relationship. Without documented approval, the individual employee bears responsibility, which can have personnel consequences if a hit occurs. A clearly managed escalation matrix prevents such misallocations and stabilizes responsibility at the right level. For business relationships with third countries, it is also worth having a written sanctions clause in the contract, which imposes on the other side the obligation to rule out breaches of sanctions and to transparently disclose their own ownership structure. In the event of a hit, such a clause creates an indication that the contract can be terminated under civil law without any claims for damages from the other party. It is not a replacement for the operational audit, but rather a contractual safeguard.
Document chain and retention requirements
Every sanction check must be verifiable, otherwise it is considered not to have been carried out. The chain of evidence includes at least: the checked data record (name, date of birth, address, beneficial owner, product or goods classification), the list version with date, the confidence class of the hit, the decision with reasons and person responsible, as well as the timestamp of the process. If there are hits, the escalation steps, the reports to the Bundesbank, BAFA or FIU as well as the communication with the customer must also be documented. The retention period is based on Section 8 of the GwG (usually 5 years, longer in special cases) and Section 257 of the German Commercial Code (HGB) for commercial documentation.
The chain of documents must be traceable in the audit. Pure log files without business context are not enough. An auditable solution links each audit process with the triggering business transaction (customer creation, order, payment receipt) and with the responsible employee. Anyone who maps this in the CIVAC workspace can display the chain of documents for supervisors, auditors or their own management in just a few clicks. Licence the workspace for your internal representatives, or have our representatives order it, depending on your own capacity. The 490 ready-to-use audit templates include, among other things, a sanctions review protocol template, a hit decision template and a report to Bundesbank template. In this way, document management can be standardised without restricting individual factual assessment. The chain of documents also includes the training certificates of the checking employees. Anyone who makes hit decisions without documented training runs the risk of the supervisory authority denying the expertise behind the decision. An annual training session with case studies, documented with a list of participants, training material and knowledge tests, closes this gap. A central training database shows who has reached what level and when, and automatically sends out reminders before the end of a training cycle.
Common mistakes and how to avoid them
First: manual checking for medium or high inventory. Anyone who manually compares the list against the list on a weekly basis will overlook any listing changes in the meantime and will not be able to provide audit evidence. Secondly: one-off check when the contract is concluded without ongoing monitoring. Listings take place at short notice, existing customers can be listed later. Third: pure name check without beneficial ownership comparison. Anyone who does not recognise the straw man risks circumventing the provision ban. Fourth: Disposal of false hits without documentation. Anyone who simply clicks away the false hit cannot later prove that the check was carried out carefully.
Fifth: Missing escalation rules. Employees without a level of training and without a clear escalation matrix make ad hoc decisions that cannot be reconstructed under pressure. Sixth: neglecting the sector sanctions because they are less visible than the lists of people. A supplier of industrial electronics to Russia has had significantly stricter obligations since 2022, even if the customer is not listed personally. Seventh: Uncalibrated thresholds that produce either too many false hits or too few hits. Quarterly calibration based on our own statistics is state of the art. Make an assignment out of reading: Anyone who discovers these errors in their own organisation should not leave them alone, but rather actively address them and include them in the next hearing report from the money laundering or export control officer so that management is involved in correcting them. Eighth and finally: Lack of emergency rules for listings of large existing customers. Anyone who finds a long-standing business partner on the list needs a prepared escalation route with the legal department, management and, if necessary, the Bundesbank. Without this plan, hours of discussions while payments continue to go through is a significant risk. A prepared emergency runbook template with phone list, template texts and decision paths can close this gap.
How CIVAC carries sanctions checks as a workflow
CIVAC is a compliance platform and officer-as-a-service with 25 officer roles, all live. For sanctions checking, this means: daily updating of the consolidated EU list with version management, fuzzy-tolerant matching engine with documented threshold values, hit process with escalation matrix, templates for Bundesbank reports, BAFA notifications and FIU suspicion reports, audit-proof document storage with timestamp and person responsible. Audit-proof, documented, § 18 AWG and § 5 GwG-proof. In addition, there is the EU data residency and the ISMS according to ISO/IEC 27001:2022 with 93 controls so that personal and business data in the audit remain at the same level of protection as the rest of compliance.
Two models are available. Licence the workspace for your internal representatives, or have our representatives order it. In the licence model, your money laundering and export control officer receives the operational infrastructure; in the mandate model, CIVAC provides the relevant officer externally, including reporting and representation. Both paths end in the same audit trail: auditable, dated, released. The auditor calls, the evidence is ready. Turn reading into an assignment. Write to info@civac.de or use the contact form at civac.de/faq for an initial indication of your document chain and your threshold calibration. You will receive a concrete assessment within the CIVAC SLA of 2 working days, instead of the classic 2 to 6 weeks lead time from external consultants. This creates a controllable process from a regulatory risk, with clear responsibilities, a documented threshold model and a chain of evidence that can withstand the next auditor or supervisor. Anyone who uses the first appointment to produce a list of gaps will then have a concrete roadmap instead of continuing to get lost in general discussions.
FAQ
Which EU sanctions regulations are relevant for an average company?
At least the regulations (EC) 881/2002, (EU) 2580/2001, (EU) 833/2014, (EU) 765/2006, (EU) 267/2012 and (EU) 36/2012, each with their current versions. There are also sectoral requirements for banks, insurance companies and exporters. Which ones are specifically binding depends on the business model, customer structure and supply chains and should be documented by the money laundering officer.
Is a weekly comparison against the EU list sufficient?
No. The EU often publishes list changes at short notice, sometimes several times a week. The state of the art is a daily pull job in the morning and an event-driven check for every new business relationship, every order and every payment. Weekly audits lead to gaps that are difficult to justify in the audit, especially in payment transactions with third countries.
How do you deal with false hits?
False hits are checked, documented and justified in writing. The documentation includes the confidence class, the distinguishing features (date of birth, address, alias name) and the identity of the key employee. Anyone who clicks away false hits without noting them loses the audit evidence. A central false hit database with suppression rules prevents repeated manual checking of the same false hit and makes quarterly evaluation easier. Sample tests ensure quality.
What happens if a sanctions hit is confirmed?
The business relationship will be frozen immediately, payments and deliveries will be stopped. The Deutsche Bundesbank is informed, and depending on the regime, BAFA is also informed. If the AMLA is involved, a suspicious transaction report is also sent to the FIU. The process must be documented in an audit-proof manner with a time stamp, people involved and receipts. Deadline begins as soon as we become aware of it. The tipping-off ban according to Section 47 GwG must be strictly adhered to.
Who is responsible in the company, the money laundering officer or the export control officer?
Both. The money laundering officer covers the AMLA side, the export control officer covers the AWG/EU sanctions side. In smaller companies the roles are often merged. It is important to have a written distribution of tasks, the escalation rules and the reporting line to management so that hit cases do not get lost between responsibilities. A representative matrix documents the distribution in a binding manner, supplemented by a substitution rule in the event of vacation or illness.
Do we need our own software or is an external service sufficient?
Both are possible. Own software solutions integrate deeply into ERP and CRM, external services reduce the maintenance effort. The chain of receipts is crucial: Anyone who uses an external solution must contractually ensure that the list version, hits and decisions are logged in an audit-proof manner and can be presented to the supervisory authority upon request. An AVV in accordance with Art. 28 GDPR also regulates data processing.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
The officer role behind this article
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.