LODLINE
EN / SV

compliance-sanctions-cyber

Sanctions screening of counterparties: what to do in the first ten days

Sanctions screening of counterparties: what to do in the first ten days comes down to three steps: freeze payment instructions pending review, run the counterparty and its beneficial owners against the current consolidated lists, and record the basis for continuing or suspending the relationship. A ten-day gap without a documented decision is itself a compliance failure.

Who this concerns

This question lands on whoever sits between the deal team and the wire transfer: in-house counsel, compliance officers, finance staff authorising payments, and directors signing off on new counterparties under time pressure. It surfaces in three recurring shapes: a screening tool returns a partial name match against a consolidated list, a customer or supplier turns out to sit behind a structure that includes a person or entity later added to a list, or an existing counterparty's ownership changes in a way that brings a designated person into the chain.

None of this is a hypothetical edge case. It is the normal output of running proper screening rather than a box-ticking check on the name in the invoice header. Most organisations already screen at onboarding. The harder question is what to do with a match, a partial match, or a structure where control sits three layers behind the registered owner, in the window before the next payment run or the next board meeting. That window is where a defensible position gets built or lost, and it is covered in detail in the sanctions and cyber practice.

What the law says

Sweden applies sanctions regimes adopted at EU level directly, alongside domestic implementing provisions and criminal liability for breach. Under Swedish law as it currently stands, the underlying prohibition attaches to the transaction itself, not to the absence of a screening procedure as such. That distinction matters in practice: a company with no formal screening policy that happens to catch a match and stops the payment is in a stronger position than a company with an elaborate policy that missed it. The obligation is one of outcome, not of paperwork, which is precisely why the paperwork still matters, as the file built during the first ten days is what demonstrates that the outcome was reached deliberately rather than by accident.

There is no single statutory checklist prescribing how internal screening has to be structured. The standard applied afterwards is whether a reasonable compliance function, given the information available at the time, would have caught the issue and acted on it within a reasonable period. That is a facts-and-timing test, and the ten-day frame used in this material reflects the operational target many organisations set for themselves rather than a fixed legal deadline.

The position changes when the counterparty, its parent, or its beneficial owners sit outside Sweden. A counterparty that is clean against the EU consolidated list can still be designated under a UN list, a UK list, or US OFAC rules that apply extraterritorially through the payment chain, correspondent banking relationships, or the nationality of goods involved. Cross-border ownership structures routinely produce conflicting screening results between databases, and a group with a foreign parent needs to check the parent's group-wide sanctions exposure, not only the counterparty entity signing the contract. Where the transaction also triggers foreign investment or merger control review, investment screening running in parallel with sanctions screening changes both the timeline and who needs to sign off before anything moves.

How it works in practice

The sequence below is what a screening hit or a partial match should trigger inside the first ten days, in the order these decisions actually get made.

Day one: freeze, don't terminate

The instinct on seeing a match is to end the relationship immediately. That instinct is usually wrong. Terminating a contract before the facts are established can itself create liability, whether for breach of contract without cause or, in the other direction, for continuing to deal with a designated person because the termination notice period kept the relationship technically alive. The correct first move is to freeze payment instructions and deliveries pending review, which preserves the position without foreclosing either outcome. Freezing is a holding action, not a legal conclusion, and it should be documented as such the same day.

Screening scope: beyond the name on the invoice

A screening exercise that stops at the counterparty's registered name is not a screening exercise, it is a formality. Scope has to extend to all known trading names, the registered and operational addresses checked separately, the beneficial ownership chain traced to actual natural persons rather than stopping at the first holding company, and the directors and authorised signatories, who are not always the same people as the shareholders. Where the counterparty sits inside a group, sister companies sharing directors or a registered address deserve the same check as the counterparty itself.

The list-hit decision tree

Not every hit is the same hit, and treating them identically wastes time and credibility. A confirmed exact match on name, date of birth, and nationality is one path: freeze immediately, escalate, document. A partial match, common name, incomplete identifying data, sits on a different path: it needs a documented reason for ruling it out, not a silent dismissal. A match on a beneficial owner rather than the contracting entity is a third path, and often the one that gets missed, because the entity itself screens clean while a person controlling 30% through two holding layers does not.

Building the file the regulator will ask for

If the position is ever questioned, what gets examined is the file, not the intention. That file should contain a timestamped record of the screening result, the identity of the person who reviewed it, the reasoning for the decision taken, any external advice sought and when, and the correspondence with the counterparty if the relationship was paused rather than continued. A decision made on day three that is only written down on day nine reads, on review, exactly like a decision made on day nine.

When internal handling is enough, and when it isn't

Straightforward false positives, common names ruled out by date of birth or nationality, can usually be closed internally with a documented rationale. Confirmed matches, ambiguous beneficial ownership structures, and any case with a cross-border dimension are a different category. The exposure at that point is not limited to the transaction itself; it extends to how corporate fines are calculated where a breach is later established, and that calculation is one reason the documentation from the first ten days carries more weight than it appears to at the time.

Re-screening triggers

A single screening check at onboarding is not sufficient protection. Consolidated lists are updated on a rolling basis, and a counterparty clean on the day of contract signing can be listed six months later without anything on the contractual side changing. Ownership changes, new financing rounds, and group restructurings are the other trigger points, and a screening programme that does not re-run on these events is, in effect, a one-time check dressed up as ongoing monitoring. Where a match is first flagged through an internal report rather than an automated tool, the route it takes matters, and internal investigation and whistleblowing channels need to connect to the sanctions escalation process rather than running as a separate, disconnected track.

What to check in the first ten days:

  • Full legal name and all known trading or former names against the current consolidated list
  • Beneficial ownership traced to natural persons, not stopped at the first intermediate holding company
  • Registered address and operational address checked separately, not assumed identical
  • Directors and authorised signatories, checked independently of the shareholder register
  • Any recent change of control, merger, or restructuring within the counterparty's group
  • Correspondent banking relationships where payment routes through a third jurisdiction
  • Existing termination and suspension clauses in the contract, reviewed before any contact with the counterparty

What do the first ten days look like when merger control runs alongside investment screening?

They run on separate clocks that occasionally converge. Sanctions screening is a standing obligation triggered by the counterparty relationship itself, while merger control and investment screening are transaction-triggered and apply only above defined thresholds. Where a deal is subject to both, the sanctions screening result feeds into the investment screening filing rather than replacing it, and a confirmed match in the first ten days will typically stop the transaction clock as well as the payment.

How are corporate fines set, and who decides the amount?

The amount reflects the severity and duration of the breach, the turnover of the entity involved, and whether the conduct was deliberate, negligent, or the result of an adequate but imperfect process. The decision sits with the competent authority for the relevant regime rather than with the courts in the first instance, though court review is available. A documented, timely response to a screening hit is treated as a mitigating factor precisely because the alternative, an undocumented delay, reads as indifference.

What does inlösen mean and why would it come up in a sanctions context?

Inlösen is the Swedish term for a statutory squeeze-out: the compulsory buy-out of minority shareholders once a controlling shareholder crosses a defined ownership threshold. It becomes relevant to sanctions work when freezing dealings with a counterparty disrupts a shareholding structure enough to trigger a squeeze-out dispute among minority holders who were not the target of the sanctions measure at all, and who may have separate legal standing to object.

The numbers

There is no statutory deadline in Swedish law requiring a decision on a screening match within a set number of days. The ten-day frame used throughout this material is an operational benchmark, not a legal cut-off, and organisations that treat it as a hard rule sometimes miss the more important point: the relevant standard is reasonableness given the facts known at the time, not a fixed calendar count.

What actually drives the cost and duration of resolving a match is the complexity of the ownership chain being traced, the number of jurisdictions whose lists have to be checked, whether the review can stay internal or needs external legal input, and whether the counterparty cooperates with requests for ownership documentation or resists them. A single-entity false positive resolved from public registry data costs and takes very little. A multi-jurisdiction structure with an uncooperative counterparty and a genuine partial match is a different scale of work entirely, and no fixed price or fixed timeline claim about it would survive contact with an actual case file.

Where it usually goes wrong

The framework above holds for the ordinary case: one counterparty, one jurisdiction, a reasonably clear ownership structure. It stops holding in a smaller number of recurring situations.

The first is conflicting results across list providers. A structure can screen clean against the EU consolidated list and flag against a UN or third-country list simultaneously, and there is no single authoritative answer that resolves the conflict; the organisation has to take a position and be able to defend why.

The second is correspondent banking freezes that occur despite a clean domestic screening result. A bank in the payment chain can freeze funds based on its own, often more conservative, screening standard, and the counterparty relationship can be entirely sound under Swedish law while the payment itself is stuck for reasons outside the counterparty's control or the reviewing company's.

The third is the ownership-dispute scenario touched on above: freezing dealings with a counterparty can precipitate a shareholder dispute, including squeeze-out claims from minority holders who were never part of the sanctions exposure, and that dispute runs on entirely different rules and timelines than the sanctions review itself.

The fourth is definitional drift in beneficial ownership. Different screening tools and different regulatory regimes define control thresholds differently, typically somewhere between 25% and 50%, and a structure engineered to sit just below one threshold can sit above another. A clean result from one tool is not evidence of anything beyond that tool's own definition.

What to do next

The first ten days are the point at which self-directed work does most of its value: freezing exposure, running the screen properly, and building a file that shows a deliberate decision rather than a delayed one. Where that work turns up a genuine match, a conflicting result across jurisdictions, or an ownership structure that does not resolve cleanly, the question stops being one of process and becomes one of exposure classification, which is a different exercise and typically needs a structured high-risk classification review rather than another round of internal screening.

Where the file already raises a genuine question about exposure or next steps, get in touch with the specifics rather than the summary; the assessment starts from the documents, not from a description of them.

Request a preliminary assessment