Screen your codes
Guide

EU sanctions compliance checklist

Enforcement rarely turns on whether a company intended to breach sanctions. It turns on whether the company can show what it checked, when, and on what basis.

Governance

Know your goods

Know your counterparty

Know the transaction

Red flags worth a documented second look

Contractual controls

Record-keeping — the part that decides cases

For each screening, retain: the code screened; the dataset or list version and the date it was run; the destination, end use and counterparties; the result; the reasoning for any derogation or exemption relied on; and who approved the decision. Retain for the period your Member State requires — commonly several years — and store it so it can be produced on request rather than reconstructed.

The purpose is not bureaucracy. If a shipment is later questioned, the file is the difference between demonstrating a functioning control and arguing from memory.

Testing and improvement

The monitoring and re-screening items are the ones that decay first in practice, because they require sustained effort with no visible output. TRADESANCTIONS.EU keeps a current dataset and can alert on changes affecting codes you have flagged, so a package amendment surfaces as a notification rather than as an audit finding. See the screening overview for how this fits the wider control, and the dual-use guide for the parallel export-control obligations.

Frequently asked questions

What should an EU sanctions compliance programme contain?
At minimum: named management-level accountability, a written and specific policy, accurate eight-digit classification of goods, screening of both goods and all counterparties in the chain, documented end-use assessment, contractual sanctions clauses, retained screening records, periodic re-screening, staff training and an annual audit sized to the company's actual exposure.
How long should sanctions screening records be kept?
Retention periods are set by Member State law and commonly run to several years. The practical standard is to retain enough to reconstruct any individual screening decision — the code, the dataset version and date, the transaction facts, the result, the reasoning and the approver — and to store it so it can be produced on request.
Who is responsible for sanctions compliance in a company?
The obligation sits with the operator, and it cannot be transferred to a customer, a freight forwarder or a software vendor by contract or by assurance. Responsibility should be assigned to a named person at management level, with defined escalation and authority to stop a shipment.
What are the main sanctions red flags?
A customer with no evident use for the item or indifference to specification and price; commercially illogical routing; newly formed intermediaries in transit jurisdictions; opaque payment structures or invoice splitting; refusal to give end-use information or to accept a no-re-export undertaking; and rising orders for goods known to be diverted.
Need the answer for a specific HS/CN code — which annex, which article, whether an exemption or wind-down applies, in any of the 24 EU languages? Run it through the TRADESANCTIONS.EU checker.