Sanctions screening of counterparties: step by step, the process runs through five stages: identify the parties and their beneficial owners, match them against the relevant restricted-party lists, assess any hit for a false positive, document the decision, and escalate a confirmed match immediately rather than waiting for a periodic review.
Who this concerns
Any company that signs a contract, extends credit, makes a payment, or takes an equity stake in a counterparty that could sit anywhere along a sanctioned ownership chain needs this procedure, not just banks and payment processors, who typically screen as a matter of licence. Corporate buyers, suppliers, joint-venture partners, and investors are exposed at the point of signature, before a wire transfer clears, and before a cross-border acquisition closes, and that exposure is frequently discovered too late because screening was treated as an onboarding formality rather than a recurring control. The sanctions, compliance and cyber practice exists precisely because this gap between "we did KYC once" and "we screen continuously" is where most exposure sits.
The exposure changes shape once a counterparty's parent, its ultimate beneficial owner, or its principal assets sit outside Sweden. A foreign holding structure does not reduce the obligation, it usually adds a jurisdiction, a registry, and a set of aliases and transliterations that need checking. Screening that stops at the contracting entity and does not follow the ownership chain to a natural person has not actually screened the transaction, it has screened a name.
What the law says
Sanctions in this area operate through a directly applicable EU framework layered onto domestic administrative and, in serious cases, criminal consequences for a breach. Under Swedish law as it currently stands, the obligation to screen is not confined to regulated financial entities: any party facilitating a transaction that would benefit a listed person or an entity owned or controlled by one carries exposure regardless of its own regulatory status. There is no published body of case law specific to this category that a company can rely on for precedent; practice in this category proceeds from the position that control, not merely a name on a list, is what triggers the obligation, and that a screening process which stops at the contracting entity's own name has not discharged it.
Separately from any regulatory duty, most cross-border contracts of any size now carry an operative sanctions clause as a condition of performance. A breach of that clause is a contractual matter in its own right, independent of whatever the regulator eventually decides, and it is frequently the faster and more predictable route to a remedy when a counterparty turns out to be exposed.
How it works in practice
Step 1: Map the parties before you screen anything
List every party the transaction actually touches: the contracting entity, its directors, its ultimate beneficial owners down to natural persons, any guarantor, and any special purpose vehicle standing between the contract and the money. Screening a trading name without mapping the structure behind it produces a clean result that means nothing.
Step 2: Establish the ownership chain
Request an organisational chart, share register extracts, and a beneficial ownership register extract, and treat the chain as unresolved, not cleared, wherever it runs through a jurisdiction with an opaque or unreliable corporate registry. A counterparty that cannot produce its own ownership chain on request is itself a finding.
Step 3: Run the match against the consolidated lists
Screen every identified party's name, known aliases, registered addresses and, where available, dates of birth against the restricted-party lists currently in force. A fuzzy or partial match is not a hit in itself, it is a lead that has to be reviewed before it is closed either way.
Step 4: Triage every hit before acting on it
Distinguish a genuine match from a name collision using documented, reproducible criteria, not analyst judgement recorded nowhere. The file a supervisor reviews later is the written rationale for closing a hit, not the analyst's recollection of why it looked fine at the time.
Step 5: Decide, document, and escalate where required
Record the clearance decision or the escalation, who made it, and when. Where a match is confirmed, escalate immediately and pause the transaction rather than proceeding while the escalation is pending; notification to the appropriate authority, where required, is made without delay under Swedish law as it currently stands, not on the next convenient reporting cycle.
Step 6: Screen again before completion, not only at intake
Lists change, ownership changes, and a counterparty cleared at onboarding can be exposed by the time a contract closes months later. Re-run screening close to signature or completion, and again periodically for any relationship that runs longer than a single transaction.
Cross-border ownership and the extraterritorial gap
The EU sanctions framework reaches entities owned or controlled by a listed person regardless of where that entity is incorporated, which means a foreign parent or holding company does not remove exposure, it usually adds a jurisdiction to check. Layered offshore structures require the same look-through to a natural person that a domestic structure would, plus a separate check on whether the offshore registry supplying the ownership data is itself reliable enough to rely on. Where a target's board previously approved a transaction on the strength of a clearance that later proves incomplete, the resolution approving it can be exposed to challenge; how an invalid board resolution plays out when the counterparty turns out to be foreign sets out that mechanism in detail.
Documents the file needs
- Onboarding and KYC form for the contracting entity
- Ownership chain diagram down to natural persons
- Beneficial ownership register extract, or the reason none was available
- Screening report showing every name checked and the list version used
- Hit-review memo for any match, including the closing rationale
- Escalation memo and, where applicable, the notification made to the authority
- The operative sanctions clause in the underlying contract
- A record of the date set for the next periodic re-screening
What to check before you sign anything
- Has the contracting entity been screened under its full legal name, not only its trading name
- Has the ownership chain been screened to the level of a natural person
- Does the screening cover known aliases and reasonable transliterations
- Has screening been repeated close to signature or completion, not only at first contact
- Is there a documented, reproducible basis for closing every hit that was raised
- Does the contract itself carry an operative sanctions clause
- Is there a written record of who approved the clearance and on what basis
What happens if a board resolution approving a transaction is later found invalid because the counterparty was sanctioned?
The resolution itself does not automatically fall away, but its validity becomes exposed to challenge once the factual basis it relied on, an apparently clean counterparty, turns out to have been wrong. The mechanics of that invalidity where the counterparty is foreign are the same regardless of which stage of screening produced the miss.
What is the company's position when an employee is investigated as a suspect in a sanctions breach?
The company's position and the employee's position are not automatically aligned, and treating them as identical from the outset is a common early mistake. How a company should position itself when an employee becomes a suspect sets out the first decisions that separate the two.
Does a sanctions-related judgment obtained in Sweden need separate recognition to be enforced in France?
Yes, in general, a Swedish judgment is not self-executing abroad; enforcement in another EU member state depends on the applicable recognition route rather than on the underlying sanctions finding itself. Recognition of a Swedish judgment in France covers the procedural route that applies once a judgment exists.
The numbers
The figures that matter most in this procedure are rarely statutory day-counts, because none apply uniformly across every instrument and every authority; the deadline attached to a specific confirmed match is set by that instrument, and where it is silent the working assumption is that notification happens without delay, before the transaction proceeds. The numbers worth tracking internally are operational: what proportion of the existing counterparty base was actually re-screened at the last periodic cycle, how many open hits sat unresolved longer than the internal escalation window allows, and how many files were cleared with no documented rationale on record. A screening programme that cannot answer those three questions has a gap in its control, whatever the written policy says.
Retention of the screening file matters more than any single deadline: it needs to survive for as long as the underlying business relationship remains open, and for the further period set by the applicable anti-money-laundering retention rule once it has ended. A cleared file that has been deleted is, for practical purposes, a file that was never screened.
Where it usually goes wrong
The most common failure is screening the contracting entity and stopping there, leaving its beneficial owners unchecked entirely. A close second is treating a clean result at onboarding as a permanent clearance rather than a snapshot that expires the moment the list, or the ownership, changes. Fuzzy hits closed informally over email, with no written rationale, are the files that look worst under later review, because there is nothing to show what was actually considered at the time. Ownership changes mid-contract, a share transfer to a newly listed party, are frequently missed because nobody re-screens an existing relationship once the initial file has been closed. Long-standing counterparty relationships are sometimes treated as grandfathered against a new listing; they are not, sanctions apply prospectively to every payment made after a listing takes effect, regardless of how long the relationship predates it.
The procedure breaks down entirely, rather than merely underperforming, where the counterparty operates through a jurisdiction with no reliable beneficial ownership registry. Screening can be executed correctly, every step followed, every document requested, and still miss the underlying control if the source data itself cannot be trusted. At that point the limit is not the screening logic, it is the reliability of what was screened against, and that limit needs to be recorded as a known gap rather than papered over with a clean-looking file. The same gap shows up in a related context where a compliance failure escalates into a reportable incident; how incident reporting deadlines apply under an energy contract illustrates how quickly an unresolved screening gap can become a separate reporting obligation in its own right.
What to do next
This procedure closes the operational gap between having a policy and running one. It does not replace a review of a specific counterparty file where the ownership chain is unclear, a hit has already surfaced, or a foreign parent has appeared partway through a long-running relationship. That is where a preliminary assessment starts: a targeted look at the file that exists today, what it is missing, and what closing that gap actually requires before the next payment is made. Book a preliminary assessment to have that specific file reviewed rather than the general policy.
Where the underlying question is less about the counterparty and more about how the screening data itself would stand up to a supervisory inspection, how a data protection inspection actually runs and what it requires sets out what an authority typically asks for once it starts looking at the records behind a screening programme.