Sanctions screening sounds like something that happens in a bank, on a floor with a compliance department and a general counsel. Most of the businesses it actually applies to have neither.
If you’re a US business paying an overseas supplier, taking payment from an unfamiliar company, or signing a deal with someone you found through a broker, the rules apply to you the same as they apply to a bank. Size isn’t a defence, and neither is not knowing.
What the lists are
The main one in the United States is the OFAC Specially Designated Nationals list — individuals, companies and vessels that US persons are prohibited from transacting with. There are others: various denied-party lists from Commerce and State, plus UN, UK and EU lists that matter if you touch those jurisdictions.
The rule is strict liability. There’s no threshold below which it stops mattering, and “we didn’t realise” isn’t a defence — although a documented screening process does count in your favour if something goes wrong.
Who actually needs to bother
Not every vendor. Screening the office coffee supplier is theatre.
The ones worth checking share features: money crossing a border, an entity you can’t easily verify, a jurisdiction with sanctions exposure, a broker or intermediary between you and whoever you’re actually paying, or a transaction big enough that being wrong would hurt.
New relationships matter more than established ones, though established ones are worth a periodic re-run. Lists change. A supplier who was clean in March may not be in November, and nobody sends you a notification.
The name-matching problem
This is where sanctions screening gets genuinely difficult, and where cheap tools fall over.
Names on these lists are frequently transliterated from other alphabets, which means one person can plausibly be spelled six different ways. Screen too loosely and you’ll get a hit on almost every common name. Screen too tightly and you’ll miss the one that matters because of a hyphen.
Then there’s ownership. An entity can be sanctioned without appearing on any list, if it’s majority-owned by parties who are. That means the name in front of you can be clean while the money behind it isn’t.
A hit is not a finding
Most hits are false positives, and treating them as accusations is both wrong and expensive.
When something flags, the job is to rule it in or out on the identifiers, not the name. Date of birth, nationality, address, passport or registration numbers. If those don’t match, you have a coincidence and you write down why you concluded that.
The written note is the part people skip and the part that matters most. A screening you can’t evidence is, from the outside, indistinguishable from no screening at all.
What this isn’t
Sanctions screening tells you whether transacting with a party is prohibited. It says nothing about whether they’re any good, whether they’ll deliver, or whether they’ll pay.
None of this is legal advice. If you have real sanctions exposure — regular cross-border payments, a supply chain running through a sensitive jurisdiction — get a lawyer who does this properly.
TellData is built for identity checks, not for employment, tenancy or credit decisions — those need an FCRA-compliant screening service.
Making it routine
The reason small businesses skip screening isn’t disagreement with it. It’s that a manual check means finding the right list, searching it, interpreting a fuzzy match and writing up the conclusion, every time.
Watchlist and sanctions screening is one of the checks inside a TellData report, run alongside identity and SSN trace, address history, court and criminal records, and phone and email consistency, with the result summarised as Clear, Review or Flag. Two minutes rather than twenty, which is the difference between a policy you follow and a policy you have.
For most small businesses the honest answer is that nothing will ever flag. That’s not a reason to skip it. It’s the reason it takes two minutes.
