Skip to content
All insights
ComplianceOctober 6, 2026 · 8 min read

Sanctions list update response: rescreening the book, holding payments and evidencing the run

A new designation starts the clock. How to run a sanctions list update response: delta rescreening, in flight payment holds, and the evidence an examiner asks for.

By Jay Kambo
Illustration — Sanctions list update response: rescreening the book, holding payments and evidencing the run
Key takeaways
  • A sanctions list update response is a drill, not a policy. Four steps in order: ingest and version the change, run a delta rescreen, deal with payments in flight, then report and record.
  • The obligation starts at publication, not when your vendor refreshes a file. EU restrictive measures take effect on publication in the Official Journal of the European Union, and FATF's Interpretive Note to Recommendation 6 describes implementation without delay as ideally within a matter of hours of a United Nations designation.
  • Run the delta rescreen before the full rescreen. Screening the whole book against only the added and amended names answers the urgent question in minutes, so the slow run never blocks the fast one.
  • Apply the ownership test every time. Per OFAC's 2014 revised guidance on entities owned by blocked persons, an entity owned 50 percent or more in the aggregate by blocked persons is itself blocked even when it is not named.
  • Keep the evidence in one record: the list version screened, the population, the hits, the disposition and reviewer for each, and the reports filed. A screening result with no list version attached cannot be reproduced.

A sanctions list update lands without warning. OFAC adds names to the Specially Designated Nationals List on no fixed schedule, and the EU and the UK publish their own changes on their own days. Your sanctions list update response is the written drill that follows: rescreen the book you already hold, hold the payments already moving, and leave an evidence trail an examiner can follow. Most institutions screen well at onboarding and at payment release. Far fewer can show what they did on the Tuesday a new name appeared.

What is a sanctions list update response, and why does it need a deadline?

It is the procedure that turns a published designation into action inside your systems. Four steps, in order: ingest the change, rescreen the existing customer and counterparty book, deal with payments in flight, then report and record.

The deadline matters because the obligation starts at publication, not at the point your vendor refreshes a file. In the United States, the prohibition attaches as soon as the designation is effective. In the European Union, restrictive measures take effect on publication in the Official Journal of the European Union, and the regulations are directly applicable in member states. The gap between publication and your last screening run is your exposure window.

FATF puts a number on the expectation. The Interpretive Note to FATF Recommendation 6 requires countries to implement targeted financial sanctions without delay, which FATF describes as ideally within a matter of hours of a United Nations Security Council designation. Supervisors read that standard back onto firms.

How quickly should you rescreen after a list update?

Set a stated service level and then meet it. A common and defensible posture is same business day for a new designation, with a documented exception path for a batch that arrives outside hours.

Three timing rules make that workable. First, pull list changes on a schedule you control rather than waiting for a vendor release note. Second, separate the full rescreen from the delta rescreen, because a delta run against only the added and amended names finishes in minutes. Third, record the list version you screened against, by date and issuer, for every run.

That last point is the one firms skip. A screening result with no list version attached cannot be reproduced, so it cannot be defended.

How do you rescreen the existing book without stopping the business?

Run the delta, triage by exposure, and keep the queue small enough that a human can clear it the same day.

  • Ingest the change and version it. Record the issuing authority, the publication date and time, the list version, and which names were added, amended or removed. Keep the raw file.
  • Run the delta rescreen first. Screen the whole book against the added and amended names only. This is the run that answers the urgent question, and it is fast.
  • Triage hits by exposure, not alphabetically. Customers with payments in flight come first, then customers with open credit or stored value, then dormant relationships.
  • Clear false positives with a written reason. Name the data point that cleared the hit: date of birth, incorporation number, country of registration, or a verified identifier.
  • Apply the ownership test. Per OFAC's 2014 revised guidance on entities owned by blocked persons, an entity owned 50 percent or more in the aggregate, directly or indirectly, by one or more blocked persons is itself blocked even if it is not named on the list.
  • Block or reject, then report. Blocking and rejecting are different actions with different reporting duties, so decide which applies before you touch the funds.
  • Run the full rescreen afterwards to catch amended spellings, new aliases and changed identifiers that a delta run can miss.
  • Close the loop in writing. One memo per list update: what changed, what you screened, how many hits, how each was resolved, and who signed it off.

The point of the order is that the slow work never blocks the urgent work. A full rescreen of a large book takes hours. A delta rescreen does not, and it is the run that keeps a prohibited payment from leaving.

What do you do with payments already in flight?

Decide this before the day arrives, because an in flight payment is where a list update becomes a live incident.

On conventional rails the leg sits with a correspondent and you ask for recall. On ISO 20022 messaging you send a camt.056 cancellation request and wait for the camt.029 answer. If the funds have already been applied, the outcome is a pacs.004 payment return rather than a cancellation. None of that is instant, and none of it is certain.

A stablecoin settlement leg changes the shape of the problem. Settlement completes in minutes, so the window to stop a payment is short, but it is honest. There is no ambiguity about whether value has moved, because the chain says so. That removes the days of uncertainty that make a conventional recall so hard to manage, and it raises the value of screening before release rather than after.

Write the rule down. Who may halt a release, what evidence they need, how a held payment is recorded, and what the customer is told. A sanctions hold is not a service failure, and your staff should not have to improvise the script.

The question an examiner asks is never whether you screen. It is what you did on the Tuesday a name was added, and whether you can prove it without rebuilding the week from memory.

What does an examiner want to see from a list update run?

A reproducible record. Not a policy document, and not a vendor dashboard.

Five artefacts cover it. The list version you screened against. The population you screened. The hits the run produced. The disposition of each hit, with the reason and the reviewer. The reports you filed and when.

Reporting duties are specific and they are short. In the United States, 31 CFR 501.603 requires a report of blocked property to OFAC within ten business days of the blocking, plus an annual report of property held as of the end of the year. Rejected transactions carry their own report. In the United Kingdom, relevant firms must inform OFSI as soon as practicable after they know or suspect that a person is designated. If the activity also raises suspicion of money laundering, a United States filer must submit a suspicious activity report within thirty calendar days of initial detection under 31 CFR 1022.320.

OFAC's own framework tells you what good looks like. The 2019 publication, A Framework for OFAC Compliance Commitments, sets out five components of a sanctions compliance programme: management commitment, risk assessment, internal controls, testing and auditing, and training. A list update drill exercises four of the five in a single afternoon, which is why it is worth rehearsing on a quiet day.

What usually goes wrong in a sanctions list update response?

The failures repeat across institutions, and they are mostly operational rather than legal.

Screening that runs only at onboarding and at release. A customer cleared in March is not cleared in October. If nothing rescreens the standing book, a designation added after onboarding is simply never seen.

Filter faults. OFAC's 2019 framework lists sanctions screening software and filter faults among the root causes of violations it has seen, including lists that were not kept current. A screening engine with a stale file reports clean and is worse than no engine, because it creates false comfort.

Single list coverage. A firm screening only the OFAC list will miss an EU, UK, UN or national designation that applies to its corridor. Match the lists to where you actually pay.

No ownership analysis. The ownership test above is where a named designation reaches an unnamed subsidiary, and a name only match will not find it.

Evidence scattered across systems. If the list version sits in one tool, the hit log in another and the decision in an email thread, the run cannot be reconstructed. That is the failure that turns a correct decision into a finding.

Finally, no rehearsal. A drill run twice a year, against a fictional name inserted into a test list, is the cheapest control on this list. It tells you your real response time instead of your intended one.

Where StableNet fits

StableNet, built by SpendTheBits, is a cross border B2B payment and settlement platform for banks, credit unions, licensed money service businesses, exchange houses and remittance fintechs. It settles in regulated stablecoins on public blockchains, in minutes, with on chain auditability, and it is ISO 20022 native, so a corridor produces pacs.008 customer credit transfers, pacs.009 interbank legs, pacs.002 status reports and pacs.004 returns, tracked end to end by UETR. Compliance is built in rather than bolted on: KYB and KYC onboarding, KYT, sanctions and PEP screening, FATF Travel Rule data in IVMS101, a compliance workbench with rescreening, and a tamper evident audit trail that holds the list version, the hit and the disposition in one record. Universal Compliance Control, the SpendTheBits submission that was named a finalist in the Swift Hackathon 2026 Technical Challenge, applies the same idea to settlement itself: an off chain compliance oracle issues one signed attestation and on chain gates enforce it identically across chains, so no valid attestation means no settlement. SpendTheBits is a Bank of Canada registered payment service provider.

See it on your corridors

Book a working session and we’ll map StableNet’s compliance and settlement to one of your live payment flows.

FAQ

Common questions

It is the written procedure an institution follows when a sanctions authority publishes a change to its list. There are four steps and the order matters: ingest and version the change, rescreen the existing customer and counterparty book against the added and amended names, deal with payments already in flight, then report and record. The output is a reproducible evidence set rather than a policy statement. Most firms screen well at onboarding and at payment release, and far fewer can show what they did on the day a new name appeared.