Zenoo
Learn/What are sanctions?
Glossary

What are sanctions?

A plain definition of sanctions plus the mechanics a compliance team is legally accountable for: the types, the lists, screening, and the ownership rule that catches firms.

Last reviewed 4 March 202612 min read
In shortThe answer, first

Sanctions are restrictive measures that a government or international body imposes on a country, entity, vessel or individual to change behaviour or protect security, without going to war. For a regulated business, complying means screening every customer, counterparty and payment against constantly changing government lists, then blocking, freezing and reporting any match.

Key facts
  • Most modern sanctions are targeted at named people, companies, sectors and vessels, not whole countries.
  • The main bodies are the UN Security Council, the US Treasury's OFAC, the EU Council, and the UK's OFSI.
  • Primary sanctions bind persons under the imposing state; secondary sanctions reach non-US parties that deal with a target.
  • Under OFAC's 50 Percent Rule, an entity owned 50% or more by blocked persons is itself blocked even when it is not named on any list.
  • Screening relies on fuzzy matching against 350-plus aggregated lists, and roughly 95% of alerts are false positives (Accenture, McKinsey, ACAMS).
  • Breaching sanctions is a strict-liability offence, and enforcement is turning criminal across the EU and UK in 2025 to 2026.

What are sanctions?

A sanction is a restrictive measure that a state or a group of states adopts to influence the conduct of a target judged to threaten international peace, security, human rights or a specific foreign-policy objective. The UN Security Council frames sanctions as a tool to maintain or restore international peace and security, sitting between diplomacy and the use of force. The US Treasury's Office of Foreign Assets Control (OFAC) describes its programmes as economic and trade restrictions used to accomplish foreign policy and national security goals. The EU calls them restrictive measures.

In everyday examples, a sanction might freeze the assets of a designated oligarch, ban the export of dual-use technology to a specific country, or prohibit a bank from processing payments for a listed vessel. For a compliance, banking, payments or trade professional, though, sanctions rarely mean the abstract policy. They mean the practical, legally enforced obligation to screen everyone you deal with against government lists, and to block anything that matches.

Why sanctions matter to a business

Breaching sanctions is generally a strict-liability offence, which means you can be penalised even if you did not intend to break the rules and did not know the counterparty was sanctioned. That is why sanctions screening is not optional housekeeping. It is a core control that banks, payment firms, insurers, crypto businesses and exporters are expected to run continuously, and it is inspected by regulators.

The stakes are rising. Global money laundering is estimated at 800 billion to 2 trillion US dollars a year, roughly 2% to 5% of global GDP (UNODC), yet less than 1% of the proceeds are ever seized or frozen. Sanctions are one of the main levers used to attack that flow, so the pressure on firms to screen well, and the penalties for failing, keep growing.

Common misconception
Sanctions do not mainly target whole countries
A sanction is a blanket ban on an entire country, so if you are not trading with a sanctioned nation you are safe.
Since the 1990s, policy has shifted decisively toward targeted or smart sanctions aimed at named individuals, companies, sectors and vessels, precisely to reduce the humanitarian harm caused by blanket country embargoes. Today the large majority of designations are person and entity specific, so a single supplier, director or ship can put you in breach.

The main types of sanctions

The word sanction covers several distinct instruments. The categories that matter most for compliance are financial, trade and sectoral measures. The table below sets out the practical taxonomy rather than the loose lists sometimes seen elsewhere.

TypeWhat it restrictsTypical example
Comprehensive sanctions and embargoesA near-total ban on trade and financial dealings with a jurisdiction. An embargo is effectively the most severe form of comprehensive sanction.US comprehensive programmes historically covering Cuba, Iran, North Korea, Syria and the Crimea region of Ukraine.
Targeted (list-based) sanctionsAsset freezes and prohibitions against named persons and entities.The US Specially Designated Nationals and Blocked Persons (SDN) List, plus the EU and UN consolidated lists.
Sectoral sanctionsRestrictions on specific industries rather than a whole economy.Limits on Russia's energy, defence and financial sectors, some captured on the US Sectoral Sanctions Identifications (SSI) List.
Financial sanctionsAsset freezes, prohibitions on making funds or economic resources available, and restrictions on capital-market access.Freezing a designated individual's bank accounts and blocking transfers to them.
Trade and export controlsBans on the supply of arms, dual-use goods, technology and specified commodities, often run by a separate agency.Export licensing controls administered in the US by the Bureau of Industry and Security (BIS).
Travel and diplomatic measuresEntry bans on named individuals, expulsion of diplomats, and suspension of cooperation.A visa ban on a designated official or the closure of an embassy.

Who imposes sanctions?

Sanctions are imposed by international bodies and by individual states, and a firm usually has to screen against several regimes at once because they do not always align. These are the four bodies to know.

BodyJurisdictionMain list
UN Security CouncilBinding on all 193 member states, administered through sanctions committees.UN Consolidated List, organised by regime (counter-terrorism, non-proliferation, conflict resolution).
OFAC (US Treasury)US persons worldwide, plus non-US parties via secondary sanctions.SDN List and the Consolidated Sanctions List, plus programme-specific lists such as the SSI List.
EU (Council of the EU)EU member states and EU operators.EU consolidated list of persons, groups and entities subject to restrictive measures.
UK (OFSI, HM Treasury)UK persons and UK activity post-Brexit.UK consolidated list of financial sanctions targets, maintained by the Office of Financial Sanctions Implementation.
Who issues sanctions: the four regimes
One firm screens all four at once. Content from the who-imposes and primary-vs-secondary sections.
UN Security Council
Binding on all 193 member states
Reach
All UN member states, via sanctions committees
Main list
UN Consolidated List, by regime
Gotcha
The baseline every other regime layers on top of
OFAC (US Treasury)
US persons worldwide, plus secondary reach
Reach
US persons, plus non-US parties via secondary sanctions
Main list
SDN List, Consolidated List, SSI List
Gotcha
Extraterritorial: a non-US bank still must screen it
EU (Council of the EU)
EU member states and operators
Reach
EU member states and EU operators
Main list
EU consolidated list of restrictive measures
Gotcha
Directive 2024/1226 turns breaches criminal
UK (OFSI, HM Treasury)
UK persons and UK activity
Reach
UK persons and UK activity post-Brexit
Main list
UK consolidated list of financial sanctions targets
Gotcha
Penalties doubling; first FI penalty landed
The screening pipeline
List ingestion
350+ aggregated lists
Fuzzy match
Name scored, not yes/no
Alert triage
~95% cleared as false positives
Block, freeze, report
Confirmed match acted on

Primary versus secondary sanctions

One distinction explains why a European bank with no US operations still cares intensely about American lists.

Primary sanctions bind persons under the imposing state's own jurisdiction. US primary sanctions apply to US persons: US citizens and permanent residents wherever they are located, entities organised under US law and their foreign branches, and anyone physically present in the US.

Secondary sanctions reach non-US parties that transact with a sanctioned target, by threatening to cut them off from the US market or financial system. They are extraterritorial by design. A firm outside the US cannot ignore OFAC lists, because dealing with a target can trigger its own loss of access to dollar clearing and US counterparties.

How sanctions screening actually works

For a regulated business, complying with sanctions is an operational process, not a legal abstraction. It runs as a pipeline, and each step introduces the false positives that dominate the workload.

  1. 1List ingestion. The firm consumes and updates dozens of government lists (OFAC SDN, OFAC Consolidated, EU, UK OFSI, UN and local regimes). Commercial data providers aggregate 350-plus lists into a single feed.
  2. 2Screening with fuzzy matching. Every customer at onboarding, every counterparty, and often every payment message is matched against those lists. Because names are transliterated, misspelt and reused, systems score the likelihood that a name in a payment equals a listed name, using phonetic, edit-distance and cultural-naming logic rather than an exact yes or no.
  3. 3Alert triage. If the similarity score crosses a configured threshold, the system raises an alert. Nothing is confirmed at this stage. An analyst compares secondary identifiers such as date of birth, nationality and address to decide match or no match. This is where most false positives are cleared.
  4. 4Block, freeze and report. A confirmed match means the firm must reject or block the transaction, freeze any assets, and report to the regulator such as OFAC or OFSI.
Common misconception
Screening is not a one-time onboarding check
Once you have screened a customer at sign-up and cleared them, you are covered.
Lists change constantly and ownership changes constantly, so a customer who was clean at onboarding can be blocked tomorrow. Effective programmes re-screen the whole book continuously rather than only at onboarding. See our guide to perpetual KYC.

The 50 Percent Rule: sanctioned without being listed

The trap that catches firms is that a company can be sanctioned without appearing on any list. Under OFAC's 50 Percent Rule, any entity owned 50% or more, directly or indirectly, in aggregate, by one or more blocked persons is itself blocked, even though OFAC never names it. The EU and UK operate similar ownership and control tests.

So a clean-looking counterparty can be effectively sanctioned through its ownership chain. Beneficial-ownership and UBO analysis is therefore inseparable from sanctions screening. Ownership is also dynamic: a clean entity today can become blocked tomorrow if a designated person raises their stake above the threshold. Building that ownership picture is where due diligence and sanctions work meet.

Why screening produces so many false positives

Fuzzy matching is deliberately generous. It has to be, because a listed person may appear in a payment under a transliterated, misspelt or partial name, and missing a real match is a breach. The cost of that caution is volume: the industry's false-positive rate on screening and monitoring alerts is widely cited at around 95% (Accenture, McKinsey, ACAMS). Analysts spend most of their time clearing alerts that were never genuine hits.

This is the pain that AI is now attacking directly. A 2025 Federal Reserve working paper (Allen and Hatfield) benchmarked four large language model families against traditional fuzzy matching on sanctions name and address screening. The models cut false positives by roughly 92% on average and improved detection rates by around 11%. The catch was latency: the models ran roughly four orders of magnitude slower, so the authors recommend a model cascade, running fast fuzzy or exact matching first and reserving the models for the uncertain cases.

Where we are now: 2025 to 2026 enforcement

Regulatory tempo is at a record high, driven largely by Russia's war on Ukraine, and enforcement is turning criminal. The timeline below sets out the load-bearing developments.

DateDevelopmentDetail
24 April 2024EU criminalisation directive adoptedDirective (EU) 2024/1226 requires member states to make sanctions violations, including breaches by gross negligence, a criminal offence, with up to 5 years' imprisonment for individuals and fines up to 5% of worldwide turnover or 40 million euros for companies.
20 May 2025EU transposition deadline passesOn 24 July 2025 the Commission opened infringement procedures against 18 member states for failing to transpose the directive in time.
July 2025EU 18th packageNew oil and petroleum measures, a transaction ban replacing the SWIFT ban for certain banks, and the first listing of a shadow-fleet captain.
23 October 2025EU 19th packageListed Russian shadow-fleet vessels rose to 557, insuring and reinsuring those vessels was banned, the Rosneft and Gazprom Neft oil-and-gas import exemption was removed, and an LNG import ban was set from 25 April 2026 for short-term contracts and 1 January 2027 for longer contracts.
2025 (full year)OFAC enforcementOFAC published enforcement totalling 262,643,459 US dollars across 13 penalties and settlements.
Early 2026OFSI reformsThe UK reported roughly 240 active investigations in April 2025, up about 40% on two years earlier, and set its maximum civil monetary penalty to double to the greater of 2 million pounds or 100% of the breach value. OFSI's first Russia-sanctions financial-institution penalty of 160,000 pounds followed.
Note
Market-size figures are directional

Analysts price the dedicated sanctions-screening-software market at roughly 1.5 billion to 2.5 billion US dollars in 2024 to 2025, growing at a compound annual rate of about 6% to 15% depending on the report (Verified Market Research, Market Research Intellect, Business Research Insights). These are vendor forecasts that disagree with each other, so treat them as a range, not a single verified number.

How AI helps in sanctions work

AI is now a genuine defensive tool in sanctions compliance, and the evidence is concrete rather than promotional. The Federal Reserve study above is the strongest case: large language models cut false positives by roughly 92% and improved detection by around 11% versus the best fuzzy baseline, with a model cascade recommended so the slow models only handle the hard cases. Beyond matching, AI can pre-classify a large share of screening alerts so analysts focus on genuine hits, and it can draft the auditable disposition notes that every sanctions decision needs.

AI on the defender’s side
Where AI genuinely helps

The defensive gains are real when AI is applied to the workflow around screening rather than to policy itself: cutting false positives through better matching and threshold tuning, triaging alerts so analysts see the ones that matter, drafting disposition notes so decisions stay defensible, and mapping ownership so the 50 Percent Rule can actually be applied to layered structures. Each of these attacks the roughly 95% false-positive burden without replacing the underlying screening data.

How AI is abused to evade sanctions

The same capabilities are being weaponised to evade sanctions, and 2025 to 2026 produced named incidents. Anthropic's August 2025 threat report documented North Korean operatives using Claude to fabricate identities, pass technical interviews and hold remote jobs at US technology firms, funnelling salaries to a sanctioned regime, and noted that AI removed the training bottleneck that once limited such operations. A related cluster used AI-generated CVs, synthetic identities and deepfake video in interviews. The US Department of Justice searched 29 suspected laptop farms across 16 states in June 2025, and CrowdStrike reported a 220% year-on-year rise in such infiltrations.

The Royal United Services Institute (RUSI), in its report Algorithms of Evasion, warns that generative AI can mass-produce high-quality fraudulent documents such as passports, bank statements, vessel registrations and invoices, authentic enough to defeat traditional compliance checks. Crypto remains the evasion rail: the Lazarus Group's 1.5 billion dollar Bybit theft in February 2025 shows sanctioned states already operate at scale in digital assets. FATF's AI and Deepfakes Horizon Scan, published in December 2025, warns that synthetic audio, video and images can defeat KYC, remote onboarding and liveness checks that many AML systems have not yet upgraded to detect.

AI as the threat
The evasion arms race

Attackers now use AI to fabricate identities and pass interviews for sanctioned regimes, forge documents at scale, and defeat biometric checks with deepfakes. As one RUSI researcher put it, static biometric checks such as a selfie or voice print are no longer sufficient proof of identity against AI-enabled adversaries. The defenders' AI advantage and the attackers' AI advantage now centre on the same layer: identity and ownership, which is exactly what sanctions compliance depends on. See synthetic identity fraud and deepfake detection in KYC.

Sanctions compliance checklist

If you run a regulated business, these are the essentials a sanctions programme has to cover.

  • Screen against every relevant regime, not just one: OFAC SDN and Consolidated, EU, UK OFSI, UN, and any local lists that apply to you.
  • Screen continuously, not only at onboarding, because lists and ownership change daily.
  • Analyse beneficial ownership so the 50 Percent Rule and its EU and UK equivalents are actually applied to layered structures.
  • Tune your thresholds so fuzzy matching catches real hits without drowning analysts in false positives.
  • Keep an immutable audit trail of every alert, disposition and override, because decisions must be defensible to a regulator.
  • Block, freeze and report confirmed matches promptly, and file to the relevant authority within the required timeframe.

What the future looks like

Several credible, attributed directions are already visible. Criminal liability is becoming the norm rather than the exception, with the EU directive and OFSI's doubled penalties pointing to prosecution rather than administrative fines, and first criminal cases expected across 2026 to 2027. Beneficial-ownership screening is becoming table stakes as the 50 Percent Rule and its analogues bite, so continuous UBO monitoring stops being a nice-to-have.

FATF frames the future explicitly as AI versus AI: firms will need to ramp up AI detection, scale human review, and invest in cross-industry collaboration, while supervisors intensify scrutiny of AI-specific controls. RUSI goes further, recommending deepfake-aware KYC and even compute-KYC obligations that monitor GPU-rental patterns, an early sign that AI infrastructure itself may become sanctions-relevant. And the Federal Reserve's cascade finding, fast matching first with models reserved for the hard cases, is likely to shape how screening stacks are architected, favouring orchestration over any single monolithic engine.

How Zenoo helps, honestly

The honest frame is your sanctions vendors plus Zenoo, never Zenoo replaces sanctions screening. Zenoo does not publish or maintain government lists, and it is not the name-matching engine that decides whether a payment name equals a listed person. Those functions belong to specialist screening providers, the kind found in Zenoo's Marketplace. Where Zenoo genuinely helps is the workflow around those vendors.

Institutions typically run several providers at once. Zenoo orchestrates across them: it routes checks, handles failover if one is down, runs checks in parallel, and keeps one immutable audit trail (32 event types across 8 categories) so every screening hit, disposition and override is traceable, which matters more as enforcement turns criminal. Its 10 specialised AI agents work on that output, not the list. The Alert Investigator agent can pre-classify up to 80% of screening alerts, resolution notes are drafted in about 10 seconds, and threshold tuning typically cuts false positives by 15% to 30%. For the 50 Percent Rule, the KYB Researcher and Full KYB Pipeline build the beneficial-ownership picture, discovering 2 to 4 times more related persons than manual processes.

Honest scope
Where Zenoo does not solve the problem

Zenoo does not decide sanctions policy or guarantee that a match is legally correct; the firm remains liable. It does not detect deepfakes or forged documents itself; it orchestrates the biometric and document-verification vendors that do. And it does not maintain sanctions lists or replace a screening provider's matching engine. Every Zenoo figure here comes from our internal metrics registry.

Key takeaways
  • Most modern sanctions are targeted at named people, companies, sectors and vessels, not whole countries.
  • The main bodies are the UN Security Council, the US Treasury's OFAC, the EU Council, and the UK's OFSI.
  • Primary sanctions bind persons under the imposing state; secondary sanctions reach non-US parties that deal with a target.
  • Under OFAC's 50 Percent Rule, an entity owned 50% or more by blocked persons is itself blocked even when it is not named on any list.
  • Screening relies on fuzzy matching against 350-plus aggregated lists, and roughly 95% of alerts are false positives (Accenture, McKinsey, ACAMS).
  • Breaching sanctions is a strict-liability offence, and enforcement is turning criminal across the EU and UK in 2025 to 2026.

Frequently asked questions

What are sanctions in simple terms?

Sanctions are penalties that a government or international body imposes on a country, company, vessel or person to change their behaviour or protect security, without going to war. They can freeze assets, ban trade or bar travel. For a business, they mean a legal duty to check who you deal with against official lists and to block anything that matches.

What are the main types of sanctions?

The main types are comprehensive sanctions and embargoes (a near-total ban on a jurisdiction), targeted or list-based sanctions against named people and entities, sectoral sanctions on specific industries, financial sanctions such as asset freezes, trade and export controls, and travel or diplomatic measures. For compliance teams, the financial, trade and sectoral measures matter most.

What is the difference between sanctions and an embargo?

An embargo is effectively the most severe form of sanction: a near-total ban on trade and financial dealings with a whole jurisdiction. Sanctions is the broader term, covering everything from a single asset freeze on one person to comprehensive country-wide bans. Put simply, every embargo is a sanction, but most sanctions are not embargoes.

Who imposes sanctions?

The four bodies to know are the UN Security Council, whose measures bind all 193 member states; OFAC, the US Treasury office behind the SDN and Consolidated lists; the Council of the EU, which adopts restrictive measures; and the UK's OFSI, which maintains the UK consolidated list post-Brexit. Firms usually have to screen against several of these regimes at once.

What is the difference between primary and secondary sanctions?

Primary sanctions bind persons under the imposing state's own jurisdiction, for example US persons in the case of OFAC. Secondary sanctions are extraterritorial: they reach non-US parties that transact with a sanctioned target, by threatening to cut them off from the US market or financial system. That is why a bank with no US operations still screens against OFAC lists.

What is the OFAC 50 Percent Rule?

Under OFAC's 50 Percent Rule, any entity owned 50% or more, directly or indirectly, in aggregate, by one or more blocked persons is itself blocked, even though OFAC never names it. So a counterparty can be effectively sanctioned through its ownership chain, which makes beneficial-ownership analysis inseparable from sanctions screening.

Why do sanctions screening systems produce so many false positives?

Screening uses fuzzy matching, which scores the likelihood that a name equals a listed name using phonetic and edit-distance logic. It is deliberately generous because missing a real match is a breach, so it flags many near-matches that are not genuine hits. The industry false-positive rate is widely cited at around 95% (Accenture, McKinsey, ACAMS), and analysts spend most of their time clearing them.
ZenooWhere this fits, honestly

Zenoo does not replace your sanctions screening vendor. It orchestrates the vendors you already use, routes and runs checks in parallel with failover, keeps one immutable audit trail, and puts 10 specialised AI agents on the workflow around screening: triage, disposition notes, threshold tuning and ownership research.

Sources

Last reviewed 4 March 2026. Every statistic is traceable to a named source.
  1. 01OFAC: Sanctions Programs and Country Information
  2. 02OFAC: Entities Owned by Blocked Persons (50 Percent Rule) FAQ
  3. 03Institute for Financial Integrity: OFAC's 50 Percent Rule
  4. 04Kharon: Sanctions 50 percent rules and beyond
  5. 05Council of the EU: Types of sanctions the EU adopts
  6. 06Council of the EU: 18th package press release (July 2025)
  7. 07K&L Gates: EU adopts 19th package of sanctions against Russia
  8. 08Ashurst: Overview of the EU's 19th sanction package
  9. 09Federal Reserve (Allen and Hatfield, 2025): Can LLMs improve sanctions screening?
  10. 10Anthropic: Detecting and countering misuse of AI, August 2025
  11. 11Crowell & Moring: North Korean remote IT worker schemes
  12. 12The Register: Rogue states putting AI agents to work on sanctions evasion
  13. 13FATF: AI and Deepfakes Horizon Scan (December 2025)
  14. 14Skadden: EU aims for harmonised sanctions enforcement (Directive 2024/1226)
  15. 15National Law Review: Commission targets 18 member states over sanctions enforcement
  16. 16White & Case: UK sanctions update: OFSI annual review
  17. 17Skadden: UK updated framework for financial sanctions enforcement (February 2026)
  18. 18LegalClarity: What are OFAC sanctions (SDN, programmes, penalties)
  19. 19sanctions.io: Primary and secondary sanctions explained
  20. 20GovFacts: Understanding sanctions versus embargoes
  21. 21Verified Market Research: Sanctions screening software market
Was this helpful?
Share