Policies and procedures · 17 MIN READ

UK sanctions screening policy template: a practical guide for accountants and law firms

Turn screening into a procedure your team can follow: clear responsibilities, sensible review triggers and evidence that explains each decision.

What should a UK sanctions screening policy include?

A useful sanctions screening policy explains who your firm checks, which sources it uses, when checks happen, who reviews possible matches and what evidence staff must keep. It also identifies the person who can pause affected work, obtain specialist advice and assess reporting duties. The procedure should connect those decisions to actual engagements and matters. A downloaded document becomes useful only when its instructions describe what your practice can and will do.

Start with the editable pack above, then use this guide to make the choices behind each clause. It contains sample wording, a staff procedure and a record you can reuse for individual checks. The examples show how a small accountancy team and a conveyancing team might allocate responsibility. They are fictional teaching examples, not client cases, legal conclusions or recommended screening intervals for every firm.

The policy should sit beside your firm-wide risk assessment, engagement or matter-opening procedures and wider financial-crime controls. GOV.UK explains that sanctions legislation does not prescribe a particular due-diligence method. The SRA also warns that a template risk assessment must reflect the practice using it. Record the reasoning behind your controls instead of presenting the template as a statutory checklist.[1][2]

  • Name the owner, deputy and person responsible for approving the policy.
  • Define the parties, sources, business activities and review triggers in scope.
  • Document match review, ownership enquiries and escalation routes.
  • Set evidence, access, retention, training and quality-review arrangements.
  • Approve a version that staff can actually follow, with a review date and change log.

Keep the policy, procedure and evidence record connected

The policy sets the decisions the firm has made: its scope, responsibilities and expectations. The procedure gives a staff member the steps to take on a file. The evidence record shows what actually happened. Keeping these three layers connected makes it easier to find the cause of a gap. A missing search may mean the procedure was unclear; a completed search with no review note may mean the record design was incomplete.

For example, the policy might require a corporate client to be assessed before engagement acceptance. The procedure identifies who collects the company details, who establishes relevant ownership information and where uncertainty is escalated. The record names the company and people checked, the sources and dates, the remaining questions and the acceptance decision. “We screen all clients” leaves each of those operational choices unanswered.

Use one approved master copy. Give it a version number, effective date, approver and location, and retain superseded versions so a later reviewer can see which instruction applied. Avoid creating separate, contradictory rules in an onboarding form, a partner email and a software help page. When the process changes, update the affected form and staff instructions together and record who was told.

Tailor the scope to your clients and services

Write a short description of your practice before choosing controls. Include the work you perform, typical client structures, relevant countries, payment arrangements, intermediaries and the points at which staff can affect a transaction. A firm preparing local sole-trader accounts needs different operational detail from one administering multi-entity groups or handling commercial property completions. The policy should explain those differences without treating a low-risk label as permission to disregard a prohibition.

For an accountancy practice, work through your actual service lines: bookkeeping, payroll, tax advice, audit and company services where provided. Note who contracts with you, who instructs you, who receives the service and whether a different entity pays. ACCA recommends considering sanctions at client acceptance and throughout the relationship. Connect that expectation to your acceptance process rather than hiding it inside a general statement about AML checks.[3]

For a legal practice, consider the matter type, parties, beneficial interests, use of client money and transaction milestones. Set out how matter teams raise changes with the responsible person. SRA guidance applies across its regulated population, including work outside the scope of the Money Laundering Regulations. Firms regulated elsewhere should use their own regulator or professional-body guidance alongside the applicable UK sanctions rules.[4]

Keep service restrictions visible. A clear name search does not answer every question about work connected with a sanctioned country or sector. For example, Russia-related professional-services restrictions require a separate assessment of the service, recipient and any applicable exception or licence. In your template, assign responsibility for that assessment and give staff a route to ask about it before agreeing to unfamiliar work.[5]

Assign decisions to people who can act

Small practices often combine responsibilities. That is a reason to be specific about who performs each task and who covers absence. Use real roles and contact details in the approved document. “Refer to compliance” is unhelpful if compliance is one partner who is on leave. Decide how urgent questions reach a deputy and when the firm will obtain outside advice.

Separate administrative completion from authority to proceed. The person entering a name can record that the search finished; the designated reviewer assesses an unresolved alert; the engagement or matter owner needs to know the resulting limits on work. State who can place and lift an internal hold, and require the reason to be recorded. The role names in the table are suggestions, not statutory appointments or a requirement to employ four different people.

Suggested allocation for a small practice
ResponsibilityDecision or actionEvidence to retain
Policy owner and deputyMaintain scope, sources, training and escalation contactsApproved version and change log
Screening operatorCheck the correct subjects and save completed resultsInputs, identifiers, source dates and results
Authorised reviewerAssess alerts and open questions; arrange advice and reporting assessmentReasoned decision and outstanding actions
Engagement or matter ownerApply the decision to the work and prevent an unauthorised next stepHold or release instruction and acknowledgement

Define who to screen and which lists to use

Build a subject list around the engagement. Begin with the contracting client, then document relevant owners, controllers, instructing parties and third-party payers. For a legal transaction, consider other parties whose identity or interest is relevant to the proposed work. Record why each subject was included and which role they hold. Avoid an unexplained instruction to screen every person mentioned in a file; staff need to understand the purpose of the check.

Distinguish the company from its trading name and the person from their business. Record legal names, known aliases and available identifiers accurately. If information is missing, state what is missing and who will obtain it. Your procedure should explain which gaps prevent the next step and which require the reviewer to assess the available evidence. A blank date-of-birth field should not be silently treated as a discrepancy that clears a match.

Maintain a list inventory with the source, provider, purpose and person responsible for checking coverage. Since 28 January 2026, the UK Sanctions List has been the sole source for current UK designations; the old OFSI Consolidated List is no longer updated. Name the current source in your procedure and confirm that any supplier feed has made the transition.[6]

Additional lists should follow the jurisdictions and obligations relevant to your work. Buying a product with UK, EU, UN and US data does not mean all those regimes apply identically to every client. Record your reasons for the selected coverage and who assesses a result outside the UK regime. Distinguish the date of the search from the list publication date and the date the provider retrieved its data; these show different parts of the evidence trail.

Give ownership and control their own review step

An entity can be affected by an asset freeze because of ownership or control by a designated person even when the entity is not listed. OFSI describes shareholding, voting, board-appointment and wider control tests. Your policy should assign the assessment separately from a company-name search, with a route for resolving uncertain structures.[7]

Companies House PSC information is a useful input, but its disclosure conditions are not a substitute for sanctions analysis. For example, the PSC shareholding condition uses more than 25%, while the sanctions ownership test described by OFSI includes more than 50% and separate control conditions. A PSC entry, an absent entry or a percentage band should not automatically produce the sanctions decision.[8][7]

In the procedure, ask the reviewer to identify the structure, date each source, record unknown intermediate owners and explain what further evidence is needed. Include a trigger for an ownership or control change after onboarding. Decide where the ownership memo is kept and how the screening operator learns about new subjects to check. This prevents company data and name-screening results from becoming two files that no one reads together.

Set review triggers that fit the work

Define the event that starts a check, the person who acts and the decision the check supports. Common operational triggers include accepting an engagement, opening a matter, a significant transaction stage, new ownership information, a new payer and a relevant list change. GOV.UK advises repeating due diligence as circumstances change. Your firm should choose and document a workable combination of event-driven checks and scheduled review.[1]

Avoid filling the template with “daily”, “monthly” or “annually” simply because another firm uses those words. Explain how the proposed timing addresses your client base, services, transaction exposure and available systems. A periodic review cannot deal with every urgent change before a payment or completion. Conversely, a policy promising continuous monitoring needs a real process for receiving changes, reviewing alerts and covering staff absence.

For each trigger, identify the queue or task where it lands. Who checks whether the task ran? What happens if the result is late? Who tells the person controlling the transaction? Document these handovers before turning on a bulk process. A batch of searches is only one part of the control; unresolved rows still need review and a decision tied to the correct engagement.

Include an outage procedure. Record which checks cannot be completed, the affected work and who decides the next safe step. If an authorised manual check is used, preserve its sources, date and limitations and reconcile the record afterwards. Do not describe an unavailable source or failed batch as a no-match result. Rehearse the procedure so staff can find it when the normal tool is unavailable.

Define escalation without turning an alert into a verdict

A matching name can belong to a different person. OFSI advises comparing identifying information and contacting it if uncertainty remains after consulting the list. Put that distinction in the procedure: staff must preserve the alert, compare evidence and explain the conclusion. A similarity score should not be treated as the probability that someone is sanctioned.[7]

Use clear internal outcomes, such as completed with no returned match, possible match under review, cleared as a different person, and escalated for restrictions assessment. Keep incomplete searches distinct. State how a plausible unresolved match affects the next payment or service decision and who can authorise further action. Cross-reference the detailed match guide below so staff have one consistent investigation workflow.

Relevant firms, including accountancy and legal businesses within the applicable definitions, must report to OFSI as soon as practicable when business information gives them knowledge or reasonable suspicion of designation or specified breaches. The report includes the basis for suspicion and identifying information; relevant customer funds or economic resources held must also be described. The policy should identify who assesses the duty and submits the appropriate report.[9]

Internal approval must not become a reason to delay a required report. Record the time the concern arose, the escalation and the action taken. Legal practices must assess privilege carefully, and firms may have separate regulator, trade-sanctions or AML reporting questions. Identify those routes in the policy. Do not assume that a bank, client or another adviser will discharge your firm’s responsibilities.[4][9]

Specify the evidence a reviewer should be able to find

Design the record around a future colleague who was not present. They should be able to reconstruct the subject, the work, the information available and the reason for the decision. A screenshot may show a result but omit the underlying input, source coverage or subsequent review. Keep the supporting documents and the decision connected by a case or matter reference. Avoid a standalone “passed” field that hides unresolved ownership or service questions.

Use the blank record in the pack as a starting point. Adapt the fields to your file system or case-management process. Set access according to role, and decide where particularly sensitive advice or privileged material belongs. Link to controlled documents where appropriate instead of copying unnecessary personal information into several spreadsheets. Staff should know how to retrieve an earlier version without overwriting the current decision.

Choose a retention schedule with the person responsible for your legal, professional and data-protection obligations. Record the category of evidence, retention trigger, duration, access rules, deletion owner and any hold that suspends deletion. This template deliberately provides no universal five-year rule for all sanctions records. An AML retention rule or a provider’s batch-storage period should not be copied into the policy without checking its scope and your reasons for keeping the information.

Minimum fields recommended for the practice record
Record groupWhat to capture
ContextClient or matter reference, proposed work, trigger and deadline
SubjectLegal name, role, identifiers, source of identity details and missing information
SearchOperator, time, lists/provider, input, source dates and completed result
AssessmentCandidate reference, comparison evidence, ownership or service questions
DecisionOutcome, rationale, reviewer, affected work and hold or release instruction
Follow-throughReports or advice references, open actions, owner and review trigger

Worked example: a small accountancy practice

Fictional scenario: a 12-person practice is accepting a UK trading company for bookkeeping and tax work. An overseas holding company owns the client, and the proposed engagement fee will be paid by a sister company. The practice’s policy assigns the engagement manager responsibility for mapping those relationships before acceptance. The screening operator receives a defined list of relevant entities and people, rather than only the trading name from the enquiry form.

The operator completes the searches and saves the inputs and results. The parent’s ultimate ownership is still unclear, so the engagement manager records the missing information and asks for supporting documents. A no-match result for the trading company is recorded accurately, while the acceptance decision remains open. The responsible partner reviews the ownership evidence and any service-restriction questions before authorising the engagement to start.

The useful policy clause is the handover: “The engagement manager confirms the subject list and unresolved ownership questions; the responsible partner approves acceptance once the documented review is complete.” The useful evidence is the relationship map, search references and reasoned acceptance note. Adaptation means substituting your firm’s real roles, tools and approval point. It does not mean copying the example’s outcome onto a client with superficially similar facts.

Test, approve and maintain the procedure

Before approval, walk through one straightforward file, one unresolved alert and one interrupted search. Check that the form captures the evidence the policy requests and that the named reviewer has access to it. Test absence cover and the handover to the person controlling an engagement or payment. Use synthetic data or an appropriately controlled training environment; do not alter real decisions simply to demonstrate a workflow.

Ask the responsible partner or suitably qualified adviser to review the regulatory scope and decisions the practice will rely on. Resolve every bracketed field, remove clauses that do not describe your arrangements and explain any additions. Record the approval, effective date, distribution and staff training. The template is an editorial resource from Sanction Search and carries no independent legal certification or regulator endorsement.

Set a planned review date and events that require earlier review: a changed service line, relevant regulatory guidance, supplier coverage changes, an incident or a recurring documentation gap. Sample the quality of decisions as well as whether searches happened. Useful questions include whether open alerts had owners, whether the next action respected the hold, and whether an exported record explains the decision without relying on the memory of its author.

  • All placeholders replaced and responsibilities accepted, including deputy cover.
  • Current sources, scope and review triggers checked against the practice’s work.
  • Blank record tested on the three training scenarios and an interrupted search.
  • Reporting and specialist-advice routes confirmed, with no automatic legal conclusions.
  • Version approved, staff briefed, evidence storage agreed and next review assigned.
Sanction Search case review screen using synthetic demonstration records
Use the case review workflow to connect the outcome and reviewer’s reasoning. The practice remains responsible for applying that decision to the work and assessing any reporting duty.

Sources & further reading

Official and professional-body sources checked on 25 September 2026. Follow the current versions when making decisions; this article is not continuously updated.

  1. UK government: starter guide to UK sanctions
  2. SRA: sanctions regime — firm-wide risk assessments
  3. ACCA: client acceptance procedures and sanctions screening
  4. SRA: complying with the UK sanctions regime
  5. Department for Business and Trade: professional and business services sanctions related to Russia
  6. FCDO: moving to a single list for UK sanctions designations
  7. OFSI: UK financial sanctions general guidance
  8. Companies House: people with significant control
  9. OFSI: reporting information to OFSI — what to do