Sanctions and PEP Screening: Requirements, Best Practices and Recent Developments
Sanctions & PEP Screening

Sanctions and PEP Screening: Requirements, Best Practices and Recent Developments

In just fifteen days, regulators and courts in the UK, the EU and the US issued a series of sanctions-related developments in 2026. First, the UK announced plans to double its maximum sanctions penalty, alongside an alert about the A7 network, which claimed to have settled more than US$86 billion in transactions. Meanwhile, the EU’s top court clarified the evidence needed to establish that a person controls a company under EU restrictive measures. At the same time, the US Treasury announced a series of actions across several countries, ranging from Iranian aviation to a crypto marketplace that Treasury said was used to launder scam proceeds.

Sanctions screening and PEP screening are related but distinct AML controls. Sanctions screening checks whether a person or entity is listed and, depending on the applicable regime, whether an unlisted company is subject to sanctions through the ownership or control of a listed person. PEP screening identifies individuals who hold or have held a prominent public function and supports the application of additional AML measures required under the applicable legal framework. Together, the sections below use this month’s UK, EU and US developments to show why both controls need attention in 2026.

For teams running a sanctions and PEP screening program, these developments have practical implications. However, most of what follows concerns sanctions and ownership and control rather than PEP-specific rules. This article therefore explains where PEP screening and sanctions screening are different disciplines. It first walks through what happened, then explains why it matters and finally sets out practical next steps for banks, fintechs, crypto exchanges and other regulated firms.

Table: Sanctions and PEP screening requirements – key controls at a glance

Compliance areaCompliance considerationWhy it matters
UK sanctions enforcementKeep evidence of screening and due diligence ready in light of OFSI’s proposed maximum penalty of the higher of £2 million or 100% of the breach valueThe UK intends to increase OFSI’s maximum penalty after the A7 network claimed to have settled more than US$86 billion in transactions
EU ownership and control analysisRecord clear, objective and checkable indicators of control rather than relying on political status or regime type aloneThe EU’s top court clarified that an authoritarian or autocratic regime, by itself, does not establish control over a company
Cross-border network screeningScreen relevant counterparties and connected entities across networks that span several countries, rather than relying only on single-entity name screeningOFAC’s September actions illustrate how sanctions-related networks can involve multiple countries and intermediary firms
Virtual asset and crypto riskExtend sanctions controls to relevant crypto counterparties, markets and payment intermediaries, not just listed wallet addressesTreasury designated a crypto marketplace that it said was used to launder scam proceeds
Sanctions license managementReview any Iran-related specific-license request against OFAC’s applicable licensing policy and its presumption of denialOFAC introduced a presumption of denial for new Iran-related specific-license requests, subject to narrow exceptions
PEP and AML risk assessmentTreat a PEP match as a risk factor requiring the additional measures applicable under the relevant legal framework, not as a sanctions hitPEP status can trigger additional AML/CFT measures under applicable law; it does not automatically prohibit the relationship

The UK announces plans to double sanctions penalties alongside A7 network alert

On August 31, 2026, the UK government announced plans for a major shift in sanctions enforcement. It said OFSI, the UK’s Office of Financial Sanctions Implementation, intends to double its statutory maximum penalty. The current maximum is the higher of £1 million or 50 percent of the breach value. Under the proposal, that would rise to the higher of £2 million or 100 percent. This change requires legislation and will be taken forward when parliamentary time allows, so it is not yet in force. Alongside the announcement, the government issued a public alert about a network called A7. Officials linked it to the Kremlin, with ties to Iranian state actors too. According to the UK government, A7 claimed to have settled more than US$86 billion in transactions in its first year. The network allegedly operated through a web of shell firms spread across several countries.

For compliance officers, the real lesson is not just the size of the proposed fine. It is the scale and complexity that sanctions-evasion networks can reach before they come to public attention. Firms should therefore treat the announcement as a prompt to strengthen their evidence of screening and due diligence. This holds even before the higher penalty takes legal effect. However, real-time sanctions-list screening alone may not identify complex evasion networks like A7, especially where relevant ownership, control or intermediary relationships are not apparent from a simple list match. Layered ownership and control analysis can therefore be important, as can regular review of high-risk partners where the firm’s risk exposure warrants it. You can read the UK government’s announcement for the full detail on the A7 alert and the proposed penalty change.

The EU clarifies the evidence needed to prove ownership and control

On September 3, 2026, the EU’s top court ruled on Case C-147/25, a reference involving the Lithuanian company Inter Rao Lietuva. The case asked a narrow question: Is an authoritarian political system alone enough to show that a state controls a company under EU restrictive measures? The court said no. Instead, national courts must satisfy themselves that the competent authority has established control on an objective and sufficiently solid basis. This means using direct evidence or a specific, precise and consistent set of indicators. Importantly, the court did not rule out political or informal influence as a relevant factor. It simply held that regime type alone cannot carry the burden of proof.

In practical terms, a firm’s link to an authoritarian state is not, by itself, evidence that the state controls that firm under the EU sanctions regime. Authorities still need objective evidence or a specific, precise and consistent set of indicators.

This judgment is directly relevant to sanctions ownership and control analysis under the EU regime. It is not a change to PEP-screening requirements, even though political exposure and beneficial ownership can overlap in practice. Ownership and control analysis can be critical to determining whether restrictive measures extend to an indirectly connected entity. It can also inform a firm’s assessment of whether restrictive measures apply to a transaction involving an indirect partner. Under the clarified standard, a file cannot establish control solely by relying on a counterparty’s nationality or the nature of the political regime. Instead, teams should document concrete indicators of control, such as board representation, voting rights, contractual arrangements and other relevant evidence. Firms working in or through the EU should revisit how their due diligence forms capture this kind of evidence. For the full reasoning, see the Court of Justice press release.

U.S. Treasury’s September sweep across aviation, crypto and terror financing

The U.S. Treasury’s Office of Foreign Assets Control (OFAC) announced a series of sanctions and enforcement actions between September 8 and September 10, 2026. Together, these actions show how widely U.S. sanctions enforcement can reach. They also illustrate why cross-border sanctions controls need to keep pace.

Iran’s aviation network

On September 8, OFAC sanctioned 36 targets for supporting Iran’s aviation sector. Most were Iranian airlines. The remaining targets included procurement intermediaries, cargo agents and individuals connected to activities in the UAE, the UK, Malaysia, Türkiye and Kazakhstan. Treasury acted under both Iran sanctions authorities and counterterrorism authorities. This illustrates how an Iran-related action can extend to third-country intermediaries that facilitate procurement or logistics, even where the intermediary is not itself Iranian.

A cross-border crypto marketplace

The next day, OFAC designated XINBI Guarantee as a Transnational Criminal Organization, describing it as an illicit online marketplace operating across Southeast Asia. Two linked technology companies, based in Cambodia and Singapore, were designated as well. Treasury said the network supported cyber scams, fraud and money laundering and processed transactions involving digital assets and fiat currency. For crypto exchanges and virtual asset firms, the action highlights why sanctions controls should not rely solely on screening listed wallet addresses. Firms should also assess relevant counterparties, entities and network relationships based on applicable requirements and risk. For virtual asset firms, sanctions controls also sit alongside applicable AML/CFT, registration and reporting obligations.

Terror financing and a tighter license policy

On September 10, OFAC named 14 people and five firms connected to networks enabling Kata’ib Hizballah and Lebanese Hizballah. The network spanned Iraq, Lebanon, Syria, Türkiye and the UAE. That same day, OFAC announced an enforcement action against an individual for providing services to companies in Iran. Furthermore, OFAC updated its Iran Statement of Licensing Policy under 31 CFR Part 560, the Iranian Transactions and Sanctions Regulations, to establish a presumption of denial for new specific-license requests except in limited circumstances. The policy includes exceptions where required by law and certain circumstances involving risks to life, health or the environment. Firms holding or seeking Iran-related licenses should reassess their licensing exposure in light of the updated policy.

Sanctions screening vs PEP screening: what’s the difference?

Compliance teams often blend these two ideas, so the distinction matters. Sanctions screening checks whether a person or entity is listed. Depending on the applicable sanctions regime, it may also require an ownership and control assessment. This checks whether an unlisted company is captured because a listed person owns or controls it. PEP screening is different. It identifies individuals who hold or have held prominent public functions and supports the application of additional AML/CFT measures required under the applicable legal framework.

A PEP match is not a sanctions match. Holding PEP status does not mean a transaction is prohibited or that the person is involved in wrongdoing. FATF’s guidance on Recommendations 12 and 22 is explicit that PEP status is a risk factor, not a presumption of wrongdoing. Depending on the applicable legal framework and the type of PEP, it can trigger additional measures. Depending on the applicable framework, this can include enhanced review of source of wealth, source of funds and beneficial ownership. FATF also cautions that commercial PEP databases are supporting tools, not a substitute for a firm’s own risk assessment. A database match is a starting point, not the end of the analysis.

None of the three developments above changes PEP-screening rules directly. The CJEU ruling addresses ownership and control under sanctions law. Likewise, the UK and U.S. actions are sanctions enforcement and designations, not PEP rulemaking. Where they do matter for PEP programs is at the edges, since political exposure, beneficial ownership and network structure often overlap in practice. A well-built program treats sanctions screening, PEP screening and ownership and control analysis as related but separate controls. Each deserves its own documentation.

Why sanctions and PEP screening keeps getting harder

Look across these developments and a pattern shows up. Sanctions evasion increasingly relies on layers of plain-looking firms. In contrast to older, cruder schemes, these layers often span several countries at once, rather than one obvious front. For example, the A7 network claimed to have settled more than US$86 billion in transactions before the UK Government announced action against it. Likewise, the Iranian aviation-related network involved targets and intermediaries across several jurisdictions beyond Iran, including the UAE, UK, Türkiye, Malaysia and Kazakhstan. Meanwhile, the XINBI Guarantee market relied on two separately incorporated technology firms based in Cambodia and Singapore.

A sanctions and PEP screening program built only around list checks may not identify this kind of activity. Effective screening needs more than watchlist checks. It also benefits from beneficial ownership analysis, network mapping and attention to higher-risk sectors and activities, including aviation-related transactions, trade finance and crypto-related activity where relevant to the firm’s risk profile. Furthermore, the Court of Justice ruling means ownership and control checks need real, objective evidence, not shortcuts based on nationality or regime type. Consequently, many firms combine screening tools with skilled human review. Automated screening benefits from that human review, especially for complex ownership, control or network relationships. Taken together, these developments show that sanctions-list screening works best alongside other controls, such as ownership and control analysis, transaction monitoring, adverse-information review and escalation.

Core sanctions and PEP screening requirements

The developments above sit on top of a baseline set of controls commonly found in sanctions and PEP screening programs. However, the list below is a high-level compliance framework, not a universal legal checklist, since exact legal requirements vary by jurisdiction and customer type.

Sanctions screening:

  • Screen against the sanctions lists that apply to your jurisdiction and business.
  • Apply ownership and control checks where the relevant regime requires them.
  • Keep evidence of each screening check and how any match was resolved.
  • In addition, update screening data promptly following new designations or other relevant list changes, in line with applicable requirements.
  • Therefore, escalate potential matches for investigation before acting on a transaction.
  • Apply the blocking, rejection or reporting steps your regime requires.

PEP screening:

  • Identify PEPs and, where required, their family members and close associates.
  • Then, apply the additional AML measures your legal framework requires for that PEP type.
  • Review source of wealth and source of funds where required.
  • In addition, assess beneficial ownership and control as part of the broader customer due diligence process, where required.
  • Document the risk assessment and the decision it led to.
  • Finally, apply ongoing monitoring and any additional measures required by the applicable legal framework for as long as those requirements apply.

Sanctions and PEP screening requirements for compliance teams

There is no single global sanctions or PEP-screening regime. The legal obligations differ by jurisdiction. Even so, a few control considerations come up again and again. These considerations are relevant to banks, fintechs, crypto exchanges and DNFBPs operating in jurisdictions such as the UAE, India, Australia, Canada, the U.S., the UK and the EU, although the precise legal requirements differ. First, revisit your sanctions risk review in light of the UK’s proposed penalty increase, OFAC’s updated licensing policy and the EU’s clarified control standard. Second, strengthen how your program records evidence of control and ownership, since regulators and courts increasingly expect specifics rather than guesswork. Third, extend screening cover to virtual asset partners and adjacent service firms, not just direct wallet matches. Treat these as risk-based controls, not a single universal checklist.

In addition, test how fast your screening system absorbs a large, multi-firm listing like the ones OFAC issued this September. Delayed list updates can increase sanctions-screening exposure following a major designation. Compliance7’s sanctions and PEP screening service helps banks, fintechs, crypto exchanges and DNFBPs build and stress-test programs against exactly these cases. This spans ownership and control checks, cross-border network screening and PEP risk assessment. Given how fast the rules shifted this quarter, a fresh look at your setup makes sense now.

Frequently asked questions

What is sanctions screening?

Sanctions screening is the process of checking customers, counterparties and other relevant parties against the sanctions lists and restrictions that apply to your business. In addition, depending on the regime, it may require an ownership and control assessment. This determines whether an unlisted entity is captured because a listed person owns or controls it.

What is PEP screening?

PEP screening identifies individuals who hold or have held a prominent public function. Consequently, it supports the additional AML measures required under the applicable legal framework.

Does being a PEP stop a business relationship?

No. Being a PEP does not automatically prevent a business relationship. Depending on the applicable legal framework and the type of PEP, the relationship may be subject to additional AML/CFT measures, enhanced due diligence and ongoing monitoring.

What is the difference between sanctions screening and PEP screening?

Sanctions screening focuses on designated persons and entities, including ownership and control rules where they apply. In contrast, PEP screening focuses on identifying political exposure and the additional AML measures a PEP relationship requires.

Does sanctions screening require beneficial ownership checks?

Depending on the applicable sanctions regime, ownership and control checks may be required. These checks can determine whether an entity is subject to sanctions even when it is not itself named on a sanctions list.

How often should sanctions and PEP screening happen?

Screening should be ongoing throughout the customer relationship, with the frequency and scope determined by applicable legal requirements and the firm’s risk-based program. In practice, this typically includes screening at onboarding, against relevant sanctions-list updates and following material changes to a customer’s circumstances, with ongoing monitoring and periodic rescreening as appropriate.

Key takeaways for compliance teams

These developments show how quickly sanctions compliance requirements, enforcement priorities and regulatory expectations can evolve. The UK has announced plans to increase OFSI’s maximum financial sanctions penalty. Separately, the EU’s top court has clarified the evidence needed to establish ownership and control under the relevant sanctions framework. Meanwhile, U.S. authorities announced a series of designations across several countries in under a week, covering areas including aviation, crypto and terrorist financing. None of these developments changes PEP-screening rules directly. Together, however, they reinforce the importance of a robust, risk-based sanctions compliance program in 2026. They also highlight why PEP screening deserves its own attention rather than being automatically folded into sanctions checks.

Compliance teams that treat these developments as one-off news risk falling behind. In contrast, teams can use them to stress-test their sanctions screening, ownership and control analysis and PEP risk assessment. This can leave them better prepared when the next designation, enforcement action or ruling arrives. If you would like an experienced team to review your current sanctions and PEP screening program, book a free consultation with Compliance7.

Related Compliance7 guides

This article is for informational purposes only and does not constitute legal or regulatory advice. For guidance specific to your business, consult a qualified compliance professional.

Ajith Abraham is a Financial Crime Compliance professional with 12+ years of experience in Anti-Money Laundering (AML), Counter-Terrorist Financing (CFT), KYC, Customer Due Diligence (CDD), Enhanced Due Diligence (EDD), Transaction Monitoring, Sanctions Screening and Financial Crime Investigations. He is a Certified Anti-Money Laundering Specialist (CAMS) and Merkle Science Certified Crypto Investigator (CCI). Ajith has worked with Big Four consulting firms and advises Financial Institutions, fintechs, DNFBPs and Virtual Asset Service Providers (VASPs) on AML/CFT compliance, risk assessments, regulatory audits, financial crime risk management, crypto compliance, blockchain investigations and FATF-aligned compliance frameworks through Compliance7 Consulting LLP.

Leave a Reply

Your email address will not be published. Required fields are marked *