
By Theodora Papadimitropoulou, head of GTM & Strategy, Third-Party Risk and Compliance.
For years, sanctions compliance was closely associated with a single task, running a counterparty’s name against the relevant lists, checking for a match and acting if required. How much that tells you, though, depends heavily on the provider and the data behind the check, and the more mature compliance teams have been moving beyond list-based screening for some time.
Regulatory expectations are moving the same way, shifting from a tick-box approach towards demonstrating a deeper understanding of evolving risks that aren’t immediately visible, such as layered ownership, circumvention and complex third-party relationships. The challenge for organisations is no longer identifying restricted entities, but understanding the broader context in which risk exists and can expose systemic risks.Where Real Exposure Now Sits
The most significant shift in recent years has been the move from identifying direct risk to understanding indirect exposure.
Take a mid-sized manufacturing supplier. On paper, it might present as an independent, locally owned business with a clean compliance record. But look one or two layers up its ownership chain and a very different picture can emerge, a holding company registered in a jurisdiction of concern or a beneficial owner linked to a sanctioned individual.
The 25% ownership rulebooks expose companies to hidden risk, so a stake kept just under that line or split across several smaller ones, can keep a risky owner off the register entirely. A name-based check against official lists wouldn’t surface any of this, because the risk sits beneath the point at which ownership has to be declared. And it’s far from rare, in indirect ownership structures especially, more than nine in 10 of the ownership changes we analysed fell short of that disclosure line.
The question is no longer whether a business is named on a list, but who owns it, who controls it, and who benefits from it, and whether restrictions are being circumvented through routes and intermediaries around it.
Criticality of Data
Knowing you need to look deeper is one thing; being able to is another. Payments may pass through several intermediaries before reaching the end supplier, and each link reduces visibility, so a team screening only the first-tier counterparty can miss a sanctioned party several steps down.
Part of the challenge is internal. Ownership records, corporate structures, sanctions data and transaction detail often sit across different systems and teams, and no one sees the full relationship. But even when that data is joined up, visibility has a harder limit.Corporate registers are national by design, so a UK or any other register, for example, shows what sits within that jurisdiction, then stops at the border. Follow the ownership into a more opaque jurisdiction and the trail can go cold, which is often exactly where the risk lies.
This is where data and analytics beyond name screening earn their place, by surfacing the patterns a single check can’t see. Businesses that appear entirely unrelated may share a registered address, the same directors may recur across companies with no obvious connection, or ownership may run through holding companies in deliberately opaque jurisdictions. No single signal is conclusive, but connected across borders they build the picture that tells a compliance team where to look, and it is this kind of corroboration, drawing on multiple sources rather than one registry, that FATF-aligned expectations call for.
From Rules-Based Screening to Intelligence-Led Compliance
Even with the right data in one place, there is a shift in mindset to make. A rules-based check answers a single question: “Is this name on a list, yes or no?”
It works for direct, disclosed relationships, but it is a snapshot taken at a single moment, usually at onboarding.
A counterparty that is clean today can look very different in six months, as sanctions lists are updated, entities are added and removed, and ownership is reworked to stay ahead of restrictions. An intelligence-led approach treats a counterparty not as a name checked once, but as a relationship worth monitoring, catching risk that emerges after onboarding rather thank missing it. It is closer to an investigative discipline, less about confirming a name is clear and more about reading the signals that a structure isn’t what it seems.
Seeing the Whole Network
None of this makes sanctions compliance simpler. If anything, it adds a layer of complexity to an already demanding function. But it reflects where genuine risk now lies, and where regulators are directing their attention.
This is where proactive risk mitigations becomes defensible. Firms that connect fragmented information and see across borders can trace ownership, question structures that don’t add up, and monitor relationships as they change, actively looking for risk rather than waiting for it to surface
When compliance is built on data that is connected across sources and verified, rather than self-declared or drawn from a single register, organisations can identify exposure before it becomes an enforcement problem, and stand behind their decisions when it matters.
Subscribe to our newsletter


