EU sanctions compliance checklist
Enforcement rarely turns on whether a company intended to breach sanctions. It turns on whether the company can show what it checked, when, and on what basis.
Governance
- Name an accountable owner for sanctions compliance at management level, not only in logistics.
- Write the policy down, and make it specific enough to act on — a statement that the company "complies with all applicable laws" is not a control.
- Define escalation: who decides when a screening result is ambiguous, and who has authority to stop a shipment.
- Size the programme to actual exposure. Destinations, product sensitivity and intermediary chains matter more than headcount.
Know your goods
- Maintain accurate eight-digit CN classifications in master data, not free-text product descriptions.
- Keep technical files sufficient to test items against dual-use control parameters.
- Classify parts, components, software and technology separately from finished goods.
- Re-validate classifications on annual CN updates and on HS revisions.
Know your counterparty
- Screen customers, consignees, end users, intermediaries, freight forwarders and banks — not just the invoiced party.
- Trace ownership and control, since designation can reach an entity through its shareholders even when the entity itself is not listed.
- Re-screen periodically. Designations are added continuously, and a cleared counterparty does not stay cleared.
Know the transaction
- Record destination, country of origin, end use and end user for every controlled shipment.
- Obtain end-user statements where the item or destination warrants it, and test them for plausibility rather than filing them unread.
- Screen on the transaction date, and re-screen long-running contracts and framework agreements.
- Include re-export and transit routes in the assessment, not only the first destination.
Red flags worth a documented second look
- A customer whose business has no evident use for the item, or who is indifferent to specification, price or delivery time.
- Routing that makes no commercial sense, or repeated changes of consignee late in a transaction.
- A newly incorporated intermediary in a transit jurisdiction with no trading history.
- Payment structures that obscure the ultimate payer, or requests to split invoices below reporting or value thresholds.
- Refusal to provide end-use information, or resistance to a no-re-export undertaking.
- Sharp growth in orders for goods of a type known to be diverted, particularly common high-priority battlefield items.
Contractual controls
- Include sanctions representations and termination rights in trading terms.
- Where the goods and destination call for it, include no-re-export undertakings with a contractual remedy — an obligation of this kind has become standard practice for goods at risk of diversion, and in some cases is expressly required.
- Pass obligations down to distributors and agents, and reserve audit rights that you actually use.
Record-keeping — the part that decides cases
For each screening, retain: the code screened; the dataset or list version and the date it was run; the destination, end use and counterparties; the result; the reasoning for any derogation or exemption relied on; and who approved the decision. Retain for the period your Member State requires — commonly several years — and store it so it can be produced on request rather than reconstructed.
The purpose is not bureaucracy. If a shipment is later questioned, the file is the difference between demonstrating a functioning control and arguing from memory.
Testing and improvement
- Audit a sample of shipments against the policy at least annually, and act on the findings.
- Train the people who actually touch transactions — sales, logistics, order entry — not only the compliance function.
- Monitor for new sanctions packages, and re-screen the catalogue when annexes change rather than waiting for the next review cycle.
- Record near-misses and stopped shipments; they are the best available evidence that the control works.
The monitoring and re-screening items are the ones that decay first in practice, because they require sustained effort with no visible output. TRADESANCTIONS.EU keeps a current dataset and can alert on changes affecting codes you have flagged, so a package amendment surfaces as a notification rather than as an audit finding. See the screening overview for how this fits the wider control, and the dual-use guide for the parallel export-control obligations.
Frequently asked questions
- What should an EU sanctions compliance programme contain?
- At minimum: named management-level accountability, a written and specific policy, accurate eight-digit classification of goods, screening of both goods and all counterparties in the chain, documented end-use assessment, contractual sanctions clauses, retained screening records, periodic re-screening, staff training and an annual audit sized to the company's actual exposure.
- How long should sanctions screening records be kept?
- Retention periods are set by Member State law and commonly run to several years. The practical standard is to retain enough to reconstruct any individual screening decision — the code, the dataset version and date, the transaction facts, the result, the reasoning and the approver — and to store it so it can be produced on request.
- Who is responsible for sanctions compliance in a company?
- The obligation sits with the operator, and it cannot be transferred to a customer, a freight forwarder or a software vendor by contract or by assurance. Responsibility should be assigned to a named person at management level, with defined escalation and authority to stop a shipment.
- What are the main sanctions red flags?
- A customer with no evident use for the item or indifference to specification and price; commercially illogical routing; newly formed intermediaries in transit jurisdictions; opaque payment structures or invoice splitting; refusal to give end-use information or to accept a no-re-export undertaking; and rising orders for goods known to be diverted.