Sectoral, blocking and sanctions that are neither
Most sanctions training stops at "check the name against the list". That covers blocking measures reasonably well and almost nothing else. This note sets out how blocking, sectoral and non-list-based measures differ in practice, and what controls you need when there is no name to screen at all.
I have lost count of the number of sanctions programmes I have reviewed where the entire control framework rested on a single assumption: that a sanctions risk arrives attached to a name. Screen the name, clear or escalate, move on. That assumption was broadly serviceable in about 2010. It has been eroding ever since, and over the past few years it has stopped holding at all.
The reason is that sanctions regimes have diversified in form, not just in volume. A designation that freezes a person's assets is one kind of instrument. A measure that says you may deal with a bank but not lend to it beyond a certain tenor is a different kind of instrument. A measure that says you may not provide shipping insurance for a commodity sold above a particular price is a third kind, and it does not mention anybody by name at all.
Juniors coming into sanctions roles tend to meet all three under one heading and assume one control covers them. It does not. Below is how I explain the difference to new analysts, and what I look for when I am assessing whether a firm can actually see the exposure it has taken on.
Blocking measures: the ones your screening engine was built for
Blocking measures — asset freezes, in UK and EU phrasing — do the thing people imagine when they hear the word sanctions. A person or entity is designated. Funds and economic resources belonging to, owned, held or controlled by that party must be frozen, and in most regimes you must not make funds or economic resources available to them, directly or indirectly, without a licence.
These measures are name-shaped. They come with identifiers: dates of birth, passport numbers, registration numbers, known aliases. A fuzzy-matching engine fed a reasonable list set and tuned sensibly will generate hits on them. The analyst's job is then discrimination — deciding whether the Mohammed Ali on the payment is the Mohammed Ali on the list — which is its own craft, and one I have written about separately in the note on clearing a sanctions name match.
The first place blocking measures stop being purely name-shaped is ownership and control. A company that is not itself designated can still be caught because of who sits above it. OFAC's approach to aggregated majority ownership and the UK's broader control test do not work identically, and the differences matter when you are deciding whether a subsidiary two jurisdictions away is in scope. I have set that out at length in the note on the fifty per cent ownership rule; the short version is that screening the payer and payee names tells you very little about who owns them.
Even so, blocking measures remain the easiest category to build for. You know what you are looking for and the authorities publish it in machine-readable form.
Sectoral measures: the counterparty is permitted, the activity is not
Sectoral measures are where the mental model starts to fail. These prohibit specific types of dealing with specific entities, while leaving the broader relationship lawful. The classic shape is a restriction on new debt above a stated maturity, or on new equity, or on certain categories of financing, imposed on named banks and energy companies that are otherwise open for business.
Think about what that does to your screening output. The name hits. The analyst looks at it, sees the counterparty is on a sectoral list rather than a blocking list, and — if the only question the workflow asks is "is this party frozen?" — clears the alert. The payment goes. Nobody has asked the question that actually governs the outcome, which is: what is this money for, and over what term?
Sectoral regimes are conditional. The condition is almost never visible in the fields a screening engine reads. A SWIFT message does not carry a tenor. A payment reference does not say "drawdown under a revolving facility originated last Tuesday". The determinative facts live in the credit file, the trade confirmation, the facility agreement — places the sanctions team is not usually looking.
So the control has to move upstream. In the teams I have run, sectoral exposure was handled at onboarding and at product level: a flag on the customer record that said, in plain terms, which activities were restricted with this counterparty and who had to approve an exception. The screening hit became a prompt to check that flag, not a decision in itself. Where the relationship ran through a correspondent chain, the problem compounded, because you may be two parties removed from whoever is actually borrowing — which is one more reason the nested correspondent relationship deserves separate treatment.
The measures that are neither
The third category has grown fastest and has no settled vocabulary. These are prohibitions attached to a thing, an activity or a price, rather than to a person. Among the forms I have had to build controls for:
- Price caps — where providing a specified service is permitted only if the underlying commodity was sold at or below a stated level, with attestation and record-keeping obligations running down the contractual chain.
- Import and export bans on defined goods, usually expressed by customs classification code rather than by product name, and frequently with origin rules that catch goods processed in a third country.
- Service prohibitions — accounting, legal advisory, management consulting, IT services, trust services — defined by what you are selling and to whom, not by any designation.
- Sectoral investment bans covering whole categories of asset rather than specific issuers.
Nothing in that list is a name. A screening engine run over a payment in which every party is clean and every field is accurate will return nothing, correctly, while the firm books a prohibited transaction. That is the structural gap, and it is not a tuning problem. You cannot tune your way to a control for something your data does not describe.
Case note
A mid-sized trade finance desk I supported ran a review in late 2023 after an internal audit point. Over the period March to November 2023 they had processed 41 payments for a freight-forwarding client, totalling about £6.9m, every one of which had cleared screening on the first pass. No designated party appeared anywhere. The client had been onboarded in 2019 and had no adverse history.
What the review found was that 14 of those payments, worth roughly £2.4m, related to voyages where the firm's facility was supporting insurance arrangements for cargo sold above the applicable cap, and a further 3 payments covered goods falling under a classification code subject to an import prohibition in the relevant jurisdiction. The attestations existed on file as scanned PDFs. Nobody in the payments chain had read them, because nothing in the workflow required anyone to. The remediation took about five months and the largest single cost was not the legal advice — it was rebuilding the product taxonomy so that a commodity code and a service type could be carried through to the payment record at all.
What the control set has to cover instead
Data you probably do not currently hold
For non-list measures you need attributes: commodity codes, country of origin and country of discharge, vessel identifiers, service category, contract tenor, underlying price. Most core banking systems were not designed to carry these to the payment layer. The honest first step is a gap assessment that says which of these attributes exist, where, and whether they are structured or sitting in a scanned attachment. In the engagements I have done, the answer is usually "in an attachment", which means a human has to read it, which means the control is a procedure rather than a system rule.
That is acceptable, provided you say so and resource it. What is not acceptable is a risk assessment that claims automated coverage the systems do not deliver. If you are writing that document now, the note on a business-wide risk assessment that survives review covers how to describe partial coverage without either overstating or sandbagging.
Document review, not just name review
Price caps and import bans are enforced through paperwork — invoices, bills of lading, certificates of origin, attestations. The skills involved overlap heavily with trade-based laundering work, where the discipline is reading a document for internal inconsistency rather than searching it for a hit. If your sanctions analysts have never been taught to read an invoice for red flags, they will not spot a cap breach, because a cap breach looks like ordinary commerce until you check the arithmetic against the date of the contract.
Decisions that belong outside the alert queue
Service prohibitions are a client acceptance question before they are a screening question. Whether your firm may provide a given service to a given category of person in a given jurisdiction is settled at the point of engagement, by legal and the business, and recorded. The sanctions team's job is to make sure that decision is recorded somewhere a payments analyst can see it at two in the afternoon on a Friday.
Testing whether you would catch it
I use the same exercise everywhere. Take three real transactions from the last quarter — not synthetic ones — and ask the team to demonstrate, with evidence, which control would have stopped each if it had breached a non-list measure. Not "screening would have flagged it". Which field, read by whom, against which reference data, at what point in the flow.
In about half the firms I have done this with, the exercise ends in silence for at least one of the three. That silence is useful. It is cheaper to find it in a workshop than in a disclosure to OFSI or OFAC, and both have been reasonably clear in their published materials that they expect firms to have considered the full shape of the regimes that apply to them, not merely the list-based parts. The Wolfsberg Group guidance on sanctions screening makes the same point from the industry side: screening is one control among several, and treating it as the control is itself a control weakness.
The framing I give new analysts is this. A blocking measure asks who. A sectoral measure asks who, and what kind of dealing. The newer measures ask what, where from, at what price, and provided by whom — and the name field may be entirely beside the point. Three questions, three sets of evidence. One engine answers the first.
Takeaway: If the only question your workflow asks is whether a name appears on a list, you have built a control for one of the three kinds of sanctions you are subject to.
