← Back to blog
Sanctions screeningAMLCompliance operations

Types of Sanctions Screening, Explained

The Screen100 Team··8 min read
Contactless payment terminal illustrating the different types of sanctions screening

Photo by Monstera Production on Pexels

Ask five compliance officers what "sanctions screening" means and you'll get five different answers, because the phrase actually covers several distinct types of sanctions screening, each catching risk at a different moment in a relationship. A bank might screen a customer once at onboarding, screen every payment message that customer sends, and re-screen the whole customer file overnight — three separate checks, doing three separate jobs. Knowing which type covers which moment, and where the gaps sit if you only run one, is the difference between a screening programme that actually works and one that just looks like it does on paper.

TL;DR: the five types of sanctions screening

  • Customer/name screening — run once when a relationship opens, against the name of the person or entity itself.
  • Transaction screening — run on every payment message, against every party named inside that specific transaction.
  • Payment screening — the card- and wire-rail flavour of transaction screening, running at the processor or network layer.
  • Batch screening — bulk re-screening of an entire customer, supplier, or counterparty list in one pass.
  • Ongoing monitoring — automatic re-screening of saved subjects every time a sanctions list updates, without anyone re-triggering it.
  • Most working compliance stacks run at least three of these together — no single type covers the whole risk window on its own.

What actually counts as sanctions screening?

Underneath all five types sits the same basic check: comparing a name — a person, a company, a vessel — against government-published designation lists, chiefly the OFAC SDN list, the OFAC Consolidated list, and the UN Security Council Consolidated list. What differs is when the check fires, what population it runs against, and how fast the answer needs to come back. A name screened at onboarding and a name screened mid-payment are using the same underlying data, but they're solving different problems, and treating them as interchangeable is where gaps creep in. If you want the fuller picture of how a single screen actually works end to end, our complete guide to sanctions screening covers that in more depth; this piece focuses specifically on how the different types split up the work.

The five types of sanctions screening, in practice

Here's what each one actually does, with a concrete example of when it fires.

Customer / name screening

This is the check most people picture first: a new customer, vendor, or counterparty comes in, and their name — along with any beneficial owners and directors — gets checked against the lists before the relationship goes live. It catches the case where the party you're about to onboard is themselves a designated person or entity. A bank opening a new business account runs this at KYC; a marketplace runs it when a new seller registers. Our walkthrough of a single OFAC check covers exactly this step in detail. OFAC's own guidance on building a compliance programme frames this as part of a broader risk assessment that should look at an organisation's customers, products, and counterparties as a connected whole, not a box to tick once — see A Framework for OFAC Compliance Commitments.

Transaction screening

Transaction screening runs on every payment instruction, not just on the account holder. A wire transfer carries several named parties — originator, beneficiary, and often one or more intermediary banks — and any one of them can be a designated party even if the account holder who initiated the payment is entirely clean. This is the check behind SWIFT message screening: every MT103 or equivalent message is parsed and each field checked before the payment is released, typically in milliseconds so it doesn't stall settlement.

Payment screening

Payment screening is close cousin to transaction screening but usually refers to the card- and instant-payment-rail version, run by processors and payment networks rather than a correspondent bank reading a SWIFT message. The mechanics are the same — check the parties, block or hold on a hit — but the volume and speed are different again: instant payment rails settle in seconds, which leaves almost no window for a slow check. OFAC has published guidance specifically addressing this, noting that firms should design screening around a risk-based assessment of a payment system's own exposure — see Sanctions Compliance Guidance for Instant Payment Systems. Instant payment volumes have made this the fastest-growing and most technically demanding of the five types.

Batch screening

Batch screening handles the population, not the moment. Instead of checking one name as it arrives, you upload an entire customer book, supplier list, or vendor register and screen it all at once. This is the tool you reach for during an acquisition (screening the target's whole customer base before close), a compliance remediation project (re-checking a legacy book that predates your current screening standard), or a periodic audit. You can try this directly — Screen100's free screening tool supports single-name lookups, and batch upload is built for exactly this kind of bulk sweep.

Ongoing / periodic monitoring

Ongoing monitoring is the connective tissue between the other four. A name that cleared at onboarding, or in last quarter's batch sweep, doesn't stay clear forever — sanctions lists update weekly or more often, so a customer can go from unlisted to designated with no transaction ever passing through your systems to trigger a check. Monitoring solves this by re-screening every saved subject automatically every time a list refreshes, and flagging anything that changes. FATF's Recommendation 10 puts this on the same footing as identity verification itself, requiring firms to conduct ongoing due diligence and scrutiny of relationships throughout their life, not just at the start — see the FATF Recommendations. Screen100's ongoing monitoring is built around this exact gap.

Screening type What triggers it What it catches Typical latency
Customer / name screeningA new relationship openingThe party itself being a designated person or entitySeconds, one-time
Transaction screeningEach payment message (e.g. SWIFT)A listed party anywhere in the payment chainMilliseconds to seconds, real time
Payment screeningEach card or instant-payment authorisationListed parties on high-speed payment railsSub-second, real time
Batch screeningA bulk upload or scheduled sweepA legacy population never checked, or screening driftMinutes, for thousands of records
Ongoing monitoringA sanctions list publishing an updateAn existing, previously clear relationship newly designatedSame day as the list refresh

What happens if you only screen at onboarding?

A payments company we spoke with (details anonymised at their request) ran a textbook onboarding check for years: every new merchant screened against OFAC and UN lists before their first transaction, filed and signed off. What they didn't have was any transaction-time or ongoing check behind it. One merchant, onboarded clean in 2019, had a beneficial owner added to the OFAC SDN list under a later sanctions programme. Nobody re-screened the file, because nothing was set up to. The company kept processing that merchant's payments for several months until a card network's own compliance audit flagged the gap — by which point remediation meant retroactive transaction reviews, a filing, and an uncomfortable conversation with a partner bank. The onboarding check hadn't failed; it had simply never been asked the question again.

As one head of compliance at a mid-sized payments firm put it plainly when we discussed this pattern: "Onboarding screening tells you who somebody was on day one. Everything after that is a different question, and if you're not asking it continuously, you're just hoping."

How do these types fit together in a real compliance stack?

In practice, the five types layer rather than compete. Customer screening is the gate at the door. Transaction and payment screening sit on the rails themselves, catching anything the gate missed or anything that changed after entry — an intermediary bank, a newly designated counterparty, a payment routed through a jurisdiction the account holder has never touched before. Batch screening is the periodic sweep that catches drift across a whole book at once, particularly useful around acquisitions or when tightening standards on a legacy portfolio. Ongoing monitoring is what keeps all of it current between events, rather than only at them.

It's also worth distinguishing sanctions screening of this kind from denied-party screening in trade and export contexts, which checks parties to a shipment or export licence rather than a financial relationship — the lists overlap but the trigger and workflow differ; our denied-party screening guide covers that version specifically. Whichever type you're building first, the starting point is the same underlying data: you can screen a name for free right now against the OFAC SDN, OFAC Consolidated, and UN Security Council lists to see what a single result looks like before deciding how to wire transaction-level or ongoing checks around it.

None of these five types is optional if your risk actually spans onboarding, payments, and time — they cover different windows, and a gap in any one leaves a specific, predictable hole. If you're only running customer screening today, the fastest next step is usually ongoing monitoring, since it closes the largest and least visible gap for the least operational change.

Frequently asked questions

What's the difference between customer screening and transaction screening?

Customer screening checks the account holder's own name once, when a relationship opens. Transaction screening checks every party named inside each payment message — originator, beneficiary, and intermediaries — every time a transaction moves, since any of those parties can be a designated person even if the account holder is clean.

Do I need transaction screening if I already screen customers at onboarding?

Yes, if payments can involve parties beyond the account holder — which most can. Onboarding screening only covers the moment a relationship starts; it can't catch a sanctioned intermediary bank, a newly designated counterparty, or a customer designated after they cleared onboarding.

How is batch screening different from ongoing monitoring?

Batch screening is a one-off (or manually scheduled) bulk check across a whole population, typically used for legacy books, acquisitions, or audits. Ongoing monitoring is continuous and automatic: saved subjects are re-screened every time a sanctions list updates, without anyone re-triggering it.

Which type of sanctions screening should a small business start with?

Customer or name screening at onboarding is the standard starting point, since it's the cheapest to implement and covers the highest-volume decision point. Add ongoing monitoring next — it closes the biggest gap (relationships that clear onboarding but are designated later) for relatively little added complexity.

Run this check on a real name

Free, no account required. Screen against the OFAC SDN, OFAC Consolidated and UN Security Council lists.