Resources · Reviewed 28 September 2026

Sanctions screening: what is required and how does it work?

No one may make funds or other assets available to a person on a sanctions list. That is why you need to check customers, beneficial owners and representatives against the lists. This guide covers the rules, the steps after a hit and how to document your work.

Sanctions screening is the check of whether a customer, or anyone connected to the customer, appears on a sanctions list. It sits alongside customer due diligence (CDD) but rests on different rules. The EU Anti-Money Laundering Regulation (AMLR), Regulation (EU) 2024/1624, applies from 10 July 2027. It makes the check an explicit part of CDD. In Sweden today, the Swedish AML Act (2017:630) applies, and it treats sanctions mainly as a risk factor.

What are sanctions and what does freezing mean?

The sanctions that apply in Sweden are decided by the UN or the EU. They can target states, groups, companies or individuals. For CDD, targeted financial sanctions matter most: asset freezes and the prohibition on making assets available.

An EU sanctions regulation shows how this works. Under Article 2 of Council Regulation (EU) No 269/2014 (Russia/Ukraine), all funds and economic resources belonging to a listed person must be frozen. No funds or economic resources may be made available to listed persons, directly or indirectly. Other sanctions regulations follow a similar pattern. Always read the regulation that your hit relates to.

EU sanctions regulations apply directly in every member state. The prohibitions bind all natural and legal persons, not only obliged entities under anti-money laundering rules.

Which rules apply to sanctions screening?

In Sweden, the rules sit in four places.

EU sanctions regulations. They contain the prohibitions, the freezing obligation and the duty to report information to the competent authority.

The Swedish International Sanctions Act (2025:327). It entered into force on 10 June 2025 and replaced the 1996 act on certain international sanctions. It contains the criminal provisions. The offence covers, among other things, intentionally or through gross negligence making property available to listed persons, or failing to freeze their property (Section 3). The Act also gives Finansinspektionen, the Swedish financial supervisor, the task of issuing temporary freezing decisions when the UN lists someone before the EU has implemented the listing (Section 20).

The Swedish AML Act. It contains no explicit rule on screening against sanctions lists. The link is in risk assessment. A customer resident in a state subject to sanctions, embargoes or similar measures is a circumstance that may indicate high risk (Chapter 2, Section 5, point 7). Screening should therefore be part of your documented CDD procedures (Chapter 2, Section 8).

AMLR from 10 July 2027. Screening becomes a CDD requirement. Under Article 20(1)(d), you must verify "whether the customer or the beneficial owners are subject to targeted financial sanctions". If the customer is a legal entity, you must also check whether sanctioned persons control it or hold more than 50% of its proprietary rights.

Who should you screen?

The prohibition covers assets that belong to, or are owned, held or controlled by, listed persons. The check therefore needs to cover more than the customer's name:

  • The customer, whether a natural or legal person.
  • Beneficial owners, including those who own or control indirectly through other companies.
  • Representatives, such as authorised signatories, board members and anyone acting under a power of attorney.
  • Counterparties in transactions, where your business handles payments.

For beneficial owners, see our guide to beneficial ownership. The same data often feeds PEP screening, but the two are separate assessments with different consequences.

When should screening take place?

Lists change often. A check at onboarding is not enough.

  1. Before the business relationship starts. Check the customer, beneficial owners and representatives before you do anything for the customer.
  2. When the lists change. Check your customer base against new listings. Under AMLR, the check must be done regularly, in proportion to your exposure (Article 26(4)). Credit and financial institutions must also check upon every new designation.
  3. When something changes at the customer. A new owner, beneficial owner, board or counterparty is a reason to screen again.

How to capture changes in the customer's circumstances is covered in our guide to ongoing monitoring.

What do you do with a hit?

A hit in a screening tool only means that one name resembles a name on a list. Your procedures should set out the steps.

  1. Establish whether it is the same person. Compare date of birth, nationality, address, company registration number and other identifiers in the list with what you know about the customer.
  2. Pause while you investigate. Carry out no transactions or assignments for the customer until you know whether the hit is genuine.
  3. Freeze if the hit is genuine. Do not deal with the assets and do not make any funds available. Exemptions require authorisation from the competent authority.
  4. Report to the competent authority. In Sweden, Finansinspektionen receives information on assets frozen under EU sanctions regulations. According to Finansinspektionen, the notification should state the listed person's name, the regulation and article, the date of the freeze, the amount or value and what has been frozen. It is sent to finansinspektionen@fi.se with "EU-sanktioner" in the subject line.
  5. Decide whether to report under AML rules. If you have reasonable grounds to suspect money laundering or terrorist financing, report to the Swedish Police Authority without delay (Chapter 4, Section 3 of the Swedish AML Act). This is a separate assessment from the freeze.
  6. Document. Record what you checked, what you concluded and who decided.

Unsure which authority is competent for a specific question, such as an exemption request? The Swedish Ministry for Foreign Affairs publishes a list of competent authorities for each regulation.

How do you handle false positives?

Most hits are false. Common names, variant spellings and transliteration produce many matches that are not the same person.

Investigate every hit with the same method. Do not dismiss a hit just because the name is common. Record the details that tell the persons apart. You can then show a reviewer why the hit was cleared, and you avoid reinvestigating it on the next run.

The Swedish data protection authority, IMY, sets the same expectation. Companies that screen must have safeguards to tell genuine hits from false ones.

What should you document?

Screening is a CDD measure. In Sweden, the records must be kept for five years (Chapter 5, Section 3 of the Swedish AML Act). At a minimum, record:

  • which persons were screened and against which lists
  • the date and version of the lists
  • each hit and how it was investigated
  • the outcome: cleared, genuine or escalated
  • who made the decision and when
  • any notification to Finansinspektionen and any report to the Police Authority

What does the Swedish data protection authority say about screening and GDPR?

Screening against sanctions lists can involve personal data relating to offences (Article 10 GDPR). Anyone other than a public authority may process such data only with a specific legal basis. This section describes the Swedish position.

EU lists. According to IMY's guidance, no permission from IMY is needed for checks against lists issued by the EU. The legal basis is Section 5, point 2 of the Swedish GDPR supplementary ordinance (2018:219), which applies when processing is necessary to fulfil a legal obligation.

Other lists. For checks against, for example, UN, US or UK lists, IMY's regulations IMYFS 2024:1 apply. Companies supervised by Finansinspektionen may carry out such checks without permission if three conditions are met (Section 6):

  • the processing is necessary to comply with the Swedish AML Act or other financial market rules
  • the lists are adopted through a democratic process and are publicly available
  • the company can distinguish genuine hits from false ones

IMY's guidance states that internal lists drawn up by companies themselves are not covered. Obliged entities outside Finansinspektionen's supervision are not covered by Section 6. They must establish their own legal basis for screening against lists other than the EU's.

In September 2026, IMY asked the European Data Protection Board for an opinion on which data Article 10 covers. Watch for changes in the interpretation.

How AKT supports the work

AKT runs the KYC process and brings documents, screening, risk assessment and the decision together in one customer file with a full audit trail. Onboarding, periodic and event-driven review happen in the same file, and a person makes the decision. Read more about the platform.

Frequently asked questions.

Does the Swedish AML Act require sanctions screening?

The Act contains no explicit rule on screening against sanctions lists. The duty to freeze and not to make assets available follows from EU sanctions regulations and applies to everyone. From 10 July 2027, AMLR requires the check as part of CDD (Article 20(1)(d)).

Where do we report a genuine hit in Sweden?

Information on frozen assets goes to Finansinspektionen, the competent authority for this under EU sanctions regulations. If there are reasonable grounds to suspect money laundering or terrorist financing, you must also report to the Police Authority under Chapter 4, Section 3 of the Swedish AML Act.

Which lists should we screen against?

EU lists apply directly and must always be included. Beyond that, your risk assessment and business decide which lists you need, for example for payments in other currencies or customers with international operations. Lists other than the EU's may require a specific legal basis under data protection rules.

Is screening at onboarding enough?

No. Lists change, and a customer's owners and representatives can change too. Check your customer base when the lists change and when the customer's circumstances change.

What happens if we miss a listed customer?

In Sweden, anyone who intentionally or through gross negligence fails to freeze property belonging to a listed person can be convicted of a sanctions offence under Section 3 of the International Sanctions Act (2025:327). The penalty is imprisonment for up to three years. A gross offence, which requires intent, carries two to six years (Section 8).

See how simple KYC can be.

Book a walkthrough and watch a customer file come together.

  1. 01You book a demo
  2. 02We prepare a relevant example
  3. 03We show the complete workflow

After the demo, you decide whether to continue with a pilot. Nothing is activated automatically.

Prefer email? contact@aktkyc.com

Book a demo of AKT

Make the demo more relevant (optional)
Required

When you submit the form, we use the details to respond to your request and plan the demo. Read our privacy policy.